MITRE ATT&CK has become the de facto standard framework for understanding adversary behaviour. Its structured taxonomy of tactics, techniques, and procedures (TTPs) provides security teams with a common language for describing threats and a structured basis for evaluating detection coverage.
Microsoft Sentinel provides the SIEM and SOAR platform on which many enterprise security operations centres now run. The integration of ATT&CK with Sentinel, mapping analytics rules to specific ATT&CK techniques enables security teams to visualise their detection coverage, identify gaps, and prioritise rule development based on the threats most relevant to their environment.
The starting point for any ATT&CK-aligned Sentinel deployment is a threat profile. This defines the adversary groups, techniques, and attack chains most likely to target the organisation based on its industry, geography, technology stack, and previous incidents. For UK financial services organisations, for example, the relevant threat actors and their preferred techniques are well documented in intelligence from the NCSC and sector-specific ISACs.
Once the threat profile is established, the next step is to map existing Sentinel analytics rules to ATT&CK technique IDs. Microsoft provides ATT&CK mappings for many of its built-in Sentinel analytics rules, but custom rules and rules imported from third-party sources often lack this metadata. FortressPoint recommends tagging all analytics rules with their corresponding ATT&CK technique IDs as a prerequisite for meaningful coverage analysis.
Coverage gap analysis involves comparing the techniques in the threat profile against the techniques covered by existing detection rules. Gaps represent detection blindspots techniques that adversaries in the threat profile use but for which the organisation has no detection capability. These gaps should be prioritised for rule development based on the likelihood and impact of the technique being used against the organisation.
KQL (Kusto Query Language) is the query language used to write Sentinel analytics rules. Effective ATT&CK-aligned detection requires KQL rules that are specific enough to detect genuine malicious behaviour while generating manageable false positive rates. FortressPoint's threat detection team develops and tunes KQL rules against the specific data sources and log formats in the customer environment.
Further reading
Speak with a FortressPoint consultant — we engage with specific questions, not just general enquiries.