MaGMa Framework
Organize your detection capabilities from business objectives to implementation. Connect ATT&CK threats to D3FEND defenses with actionable detection rules.
Framework Overview
The Three-Layer Hierarchy
Business objectives and risk-based use cases that drive detection priorities. Aligned with compliance frameworks.
Threat-level use cases mapped to ATT&CK techniques and D3FEND countermeasures. Bridges business to technical.
Concrete detection rules (Sigma, KQL, SPL) with data sources, test cases, and false positive guidance.
How MaGMa Integrates with Purple Team
ATT&CK Mapping
Every L2 use case maps to specific ATT&CK techniques, connecting your detections to adversary behaviors.
Explore ATT&CK HubD3FEND Mapping
Each use case connects to D3FEND defensive techniques, showing how your detections support defense-in-depth.
Explore D3FEND HubPurple Team Coverage
Use the Purple Team Matrix to see how your MaGMa use cases contribute to overall detection coverage.
View Purple MatrixCompliance Tracking
L1 use cases link to compliance frameworks (PCI-DSS, HIPAA, SOX), helping demonstrate regulatory coverage.
Filter by framework in the hierarchy above