Loading
Loading
Reference library
A detection needs a reason before it has syntax. Walk each use case from a business objective, to the threat that matters, to the implementation you can test.
01
The objective the organization is protecting: ransomware, unauthorized access, data leaving the network. Name the risk before you name a rule.
02
The adversary behavior that puts that objective at risk. Map enterprise behavior to MITRE ATT&CK and the MITRE D3FEND countermeasures that answer it. Map attacks on AI and ML systems to MITRE ATLAS.
03
The detection or control itself: a Sigma, KQL, or similar rule, the data source it needs, how you test it, and what a false positive looks like. AI-system detections cite the ATLAS technique they cover.
Engagement
These pages are the public method. The audit reviews the AI-related detections and agent telemetry already in an environment and returns a coverage map, the broken or missing use cases, and a prioritized backlog.
L1 to L3
UC-L1-001 · critical risk
Prevent encryption of critical business data and ensure rapid recovery from ransomware attacks to minimize operational impact.
UC-L2-001
Monitor for rapid file modifications and ransom note creation indicating active ransomware encryption.
UC-L2-002
Block common ransomware delivery mechanisms including phishing emails and exploit kits.
UC-L2-003
Monitor for attempts to delete or encrypt backup data, a common ransomware tactic.
UC-L1-002 · critical risk
Identify and respond to unauthorized access attempts to protect sensitive data and maintain compliance with access control requirements.
UC-L2-004
Identify password spraying, credential stuffing, and brute force login attempts.
UC-L2-005
Monitor for credential dumping tools and techniques targeting password stores.
UC-L2-006
Identify logins from geographically impossible locations indicating account compromise.
UC-L1-003 · high risk
Detect and prevent unauthorized transfer of sensitive data outside the organization to protect intellectual property and customer data.
UC-L2-007
Monitor for unusual data transfer volumes indicating potential exfiltration.
UC-L2-008
Identify data exfiltration via DNS tunneling and encoded DNS queries.
UC-L1-004 · high risk
Identify malicious or negligent actions by employees, contractors, or partners that could harm the organization.
UC-L2-009
Monitor for employees accessing data outside their normal patterns or permissions.
UC-L2-010
Identify misuse of privileged access by administrators or service accounts.
UC-L1-005 · high risk
Prevent phishing, business email compromise, and malware delivery via email to protect employees and business operations.
UC-L2-011
Identify phishing attempts including credential harvesting and malware delivery.
UC-L2-012
Identify impersonation attempts and fraudulent payment requests.
UC-L1-006 · high risk
Detect and respond to threats targeting cloud infrastructure, ensuring proper configuration and access controls.
UC-L2-013
Identify insecure cloud configurations that could expose data or systems.
UC-L2-014
Monitor cloud API access for unauthorized or anomalous activity.
UC-L1-007 · high risk
Identify malware presence on endpoints and servers to prevent data theft, system damage, and lateral movement.
UC-L2-015
Identify malicious process execution and suspicious command-line activity.
UC-L2-016
Monitor for malware establishing persistence via autostart or scheduled tasks.
UC-L1-008 · medium risk
Detect unusual network behavior that may indicate compromise, data exfiltration, or command-and-control communications.
UC-L2-017
Identify command-and-control traffic patterns including beaconing behavior.
UC-L2-018
Monitor for internal network movement between systems.
UC-L1-009 · critical risk
Secure Active Directory, identity providers, and authentication systems from compromise and abuse.
UC-L2-019
Identify attempts to crack service account passwords via Kerberos ticket requests.
UC-L2-020
Monitor for domain controller replication requests from non-DC sources.
UC-L1-010 · critical risk
Detect and respond to attacks that could disrupt business operations, including DoS attacks and destructive malware.
UC-L2-021
Monitor for attempts to stop critical services or disable security controls.
UC-L2-022
Identify disk wiping, master boot record destruction, and data destruction attempts.
AI-system use cases are mapped to MITRE ATLAS. The rest of the estate maps to MITRE ATT&CK and MITRE D3FEND.
Public MITRE knowledge bases. ATT&CK for adversary behavior, D3FEND for defensive countermeasures, ATLAS for attacks on AI and ML systems.