Every AlertKick detection rule is mapped to the MITRE ATT&CK framework - the industry-standard catalogue of attacker tactics and techniques. This page is the full matrix, generated from the same rule definitions the agent runs, so you can see exactly what's covered before you install anything.
74
mapped detection rules
45
ATT&CK techniques
12/12
tactics covered
Rules fire on kernel-level eBPF events - process execution, network connections, file changes, logins - so coverage below is runtime detection on the host, not log parsing after the fact. Every event a rule produces is triaged by AI and feeds compliance evidence automatically.
TA0001 · 5 techniques
| Technique | Detection rules |
|---|---|
| T1005 |
|
| T1021.004 |
|
| T1078 |
|
| T1133 |
|
| T1548.003 |
|
TA0002 · 5 techniques
TA0003 · 9 techniques
| Technique | Detection rules |
|---|---|
| T1014 |
|
| T1053.003 |
|
| T1098 |
|
| T1098.004 |
|
| T1547.006 |
|
| T1556 |
|
| T1556.003 |
|
| T1571 |
|
| T1574.006 |
|
TA0004 · 8 techniques
| Technique | Detection rules |
|---|---|
| T1055.008 |
|
| T1059 |
|
| T1068 |
|
| T1078 |
|
| T1110 |
|
| T1548 |
|
| T1548.003 |
|
| T1611 |
|
TA0005 · 11 techniques
| Technique | Detection rules |
|---|---|
| T1014 |
|
| T1055 |
|
| T1055.008 |
|
| T1070.002 |
|
| T1547.006 |
|
| T1554 |
|
| T1562.001 |
|
| T1564 |
|
| T1565.001 |
|
| T1574.006 |
|
| T1611 |
|
TA0006 · 9 techniques
| Technique | Detection rules |
|---|---|
| T1005 |
|
| T1098 |
|
| T1110 |
|
| T1110.001 |
|
| T1548.003 |
|
| T1552.001 |
|
| T1552.004 |
|
| T1556 |
|
| T1556.003 |
|
TA0007 · 2 techniques
TA0008 · 6 techniques
| Technique | Detection rules |
|---|---|
| T1021 |
|
| T1021.004 |
|
| T1071 |
|
| T1078 |
|
| T1133 |
|
| T1219 |
|
TA0009 · 3 techniques
| Technique | Detection rules |
|---|---|
| T1005 |
|
| T1078 |
|
| T1552.001 |
|
TA0010 · 5 techniques
| Technique | Detection rules |
|---|---|
| T1030 |
|
| T1048 |
|
| T1048.003 |
|
| T1071.004 |
|
| T1568.002 |
|
TA0011 · 10 techniques
| Technique | Detection rules |
|---|---|
| T1021 |
|
| T1048.003 |
|
| T1059.004 |
|
| T1071 |
|
| T1071.004 |
|
| T1105 |
|
| T1219 |
|
| T1496 |
|
| T1568.002 |
|
| T1571 |
|
TA0040 · 4 techniques
| Technique | Detection rules |
|---|---|
| T1489 |
|
| T1496 |
|
| T1554 |
|
| T1565.001 |
|
Generated from AlertKick's rule definitions (74 of 77 rules carry ATT&CK mappings; the remainder are operational checks outside the framework's scope). Technique IDs link to the corresponding MITRE ATT&CK entry.
Install one agent. Get security monitoring, infrastructure alerts, and on-call management - all included with every host.