MITRE ATT&CK

Detection by tactic.

How GhostAnalyst detection maps to the MITRE ATT&CK framework. GhostAnalyst applies layered detection across the attack lifecycle.

Sigma
Signature-based rule matching on normalised events
Cordon
Semantic anomaly detection
Vigil
Behavioural monitoring
Flux
Baseline / drift detection
Clickdetect
Escalation analysis
01Reconnaissance
CordonFlux
02Resource Development
Sigma
03Initial Access
SigmaCordon
04Execution
SigmaVigil
05Persistence
SigmaVigil
06Privilege Escalation
SigmaVigil
07Defense Evasion
CordonFlux
08Credential Access
SigmaVigil
09Discovery
CordonVigil
10Lateral Movement
CordonVigil
11Collection
VigilCordon
12Command and Control
SigmaCordon
13Exfiltration
SigmaCordon
14Impact
SigmaVigilClickdetect

GhostAnalyst applies layered detection across the MITRE ATT&CK lifecycle. This page describes detection approach by tactic, not a guarantee of coverage for every technique. Technique-level detail is available on request for specific environments.

Chat with us