Organize your detection capabilities from business objectives to implementation. Connect ATT&CK threats to D3FEND defenses with actionable detection rules.
Business objectives and risk-based use cases that drive detection priorities. Aligned with compliance frameworks.
Threat-level use cases mapped to ATT&CK techniques and D3FEND countermeasures. Bridges business to technical.
Concrete detection rules (Sigma, KQL, SPL) with data sources, test cases, and false positive guidance.
Every L2 use case maps to specific ATT&CK techniques, connecting your detections to adversary behaviors.
Explore ATT&CK HubEach use case connects to D3FEND defensive techniques, showing how your detections support defense-in-depth.
Explore D3FEND HubUse the Purple Team Matrix to see how your MaGMa use cases contribute to overall detection coverage.
View Purple MatrixL1 use cases link to compliance frameworks (PCI-DSS, HIPAA, SOX), helping demonstrate regulatory coverage.
Filter by framework in the hierarchy above