COPS MITRE ATT&CK Coverage Matrix
[!IMPORTANT] ATT&CK mappings represent planning evidence and investigative structure, not proof of control effectiveness. Coverage claims distinguish between verified analytics and unverified proposals. Match criteria retain uncertainty, and reports never assume absence of alerts indicates absence of adversary activity.
Summary Metrics
| Metric | Count | Description |
|---|---|---|
| Total Mappings | 29 | Total capability-to-technique associations |
| Distinct Techniques | 18 | Unique ATT&CK techniques and sub-techniques |
| Validated Analytics | 28 | Backed by automated deterministic offline test fixtures |
| Unverified / Experimental | 1 | Draft analytics without automated test verification |
| Detective Coverage | 15 | Threat hunting and detection engineering queries |
| Investigative Coverage | 9 | Deep-dive triage, entity tracing, and path analysis |
| Preventive Coverage | 3 | Telemetry posture and configuration recommendations |
| Response Coverage | 2 | Incident timeline and case handoff workflows |
Capabilities and Techniques
| Technique ID | Technique Name | Tactic | Capability | Evidence Source | Role | Validation | Key Limitations |
|---|---|---|---|---|---|---|---|
T1114.003 |
Email Forwarding Rule | collection |
sentinel-hunt-workbench(H07) |
Microsoft 365: OfficeActivity |
detection |
Validated | Authorized business forwarding rules require analyst confirmation |
T1213.002 |
SharePoint | collection |
sentinel-hunt-workbench(H08) |
Microsoft 365: OfficeActivity |
detection |
Validated | OneDrive sync engine performs bulk operations during initial machine con… |
T1530 |
Data from Cloud Storage | collection |
sentinel-hunt-workbench(H-PREVIEW-STORAGE) |
Azure: StorageBlobLogs |
detection |
Unverified (Draft) | Experimental draft query without deterministic test fixture verification |
T1071.001 |
Web Protocols | command-and-control |
sentinel-hunt-workbench(H04) |
Defender for Endpoint: DeviceNetworkEvents |
detection |
Validated | High-volume web browsing and SaaS integrations create noisy baseline tra… |
T1071.001 |
Web Protocols | command-and-control |
sentinel-hunt-workbench(H06) |
Defender for Endpoint: DeviceNetworkEvents |
detection |
Validated | Jitter algorithms or long sleep timers bypass interval heuristics |
T1071.001 |
Web Protocols | command-and-control |
threat-intelligence-enrichment(ti-enrichment) |
ThreatIntelligence: ThreatIntelIndicators |
investigation |
Validated | Provenance and confidence depend on external threat intelligence feed qu… |
T1105 |
Ingress Tool Transfer | command-and-control |
sentinel-hunt-workbench(H03) |
Defender for Endpoint: DeviceFileEvents |
detection |
Validated | Legitimate software updates routinely download files to temporary direct… |
T1110.003 |
Password Spraying | credential-access |
sentinel-hunt-workbench(H01) |
Sentinel: SigninLogs |
detection |
Validated | NAT or proxy concentration can aggregate distinct failures |
T1078 |
Valid Accounts | defense-evasion |
sentinel-hunt-workbench(H02) |
Sentinel: SigninLogs |
detection |
Validated | VPN roaming and legitimate travel can trigger anomalous location alerts |
T1078 |
Valid Accounts | defense-evasion |
incident-response-sandbox(containment-plan-rehearsal) |
IncidentPlan: ContainmentReceipt |
response |
Validated | Produces approval-gated cryptographic execution receipts; does not mutat… |
T1078 |
Valid Accounts | defense-evasion |
soc-investigation-workbench(export-handoff) |
Sentinel: SigninLogs |
response |
Validated | Produces structured reporting; does not perform active tenant remediation |
T1562.001 |
Disable or Modify Tools | defense-evasion |
security-logging-advisor(logging-recommendations) |
Azure: DiagnosticSettings |
prevention |
Validated | Checks static telemetry policies; does not monitor real-time sensor tamp… |
T1562.001 |
Disable or Modify Tools | defense-evasion |
telemetry-proof-pack(telemetry-route-verification) |
Cribl: RouteMetrics |
prevention |
Validated | Validates route topologies and synthetic health proofs; does not monitor… |
T1580 |
Cloud Infrastructure Discovery | discovery |
attack-surface-planner(attack-surface-scope) |
Azure: ResourceGraph |
investigation |
Validated | Performs passive boundary check only; does not perform active network sc… |
T1059 |
Command and Scripting Interpreter | execution |
sentinel-hunt-workbench(H03) |
Defender for Endpoint: DeviceProcessEvents |
detection |
Validated | Administrative automation and orchestration scripts can match heuristic … |
T1059.001 |
PowerShell | execution |
detection-quality-workbench(detection-quality-regression) |
Sentinel: DeviceProcessEvents |
detection |
Validated | Validates query syntax and true/false positive regression benchmarks; do… |
T1078 |
Valid Accounts | initial-access |
sentinel-hunt-workbench(H01) |
Sentinel: SigninLogs |
investigation |
Validated | A successful authentication following spray failures is consistent with … |
T1078 |
Valid Accounts | initial-access |
soc-investigation-workbench(intake) |
Sentinel: SigninLogs |
investigation |
Validated | Requires UTC timestamp normalization and consistent entity hashing acros… |
T1190 |
Exploit Public-Facing Application | initial-access |
exposure-triage-workbench(exposure-triage) |
Defender: SecurityAlert |
investigation |
Validated | Prioritization indicates reachability and exposure potential, not confir… |
T1190 |
Exploit Public-Facing Application | initial-access |
patch-security-review(patch-security-review) |
Git: PullRequestDiff |
prevention |
Validated | Evaluates diff heuristics offline; does not execute dynamic application … |
T1566.002 |
Spearphishing Link | initial-access |
sentinel-hunt-workbench(H09) |
Defender for Office 365: UrlClickEvents |
detection |
Validated | Automated mail gateway scanners and link evaluation bots can produce cli… |
T1021 |
Remote Services | lateral-movement |
sentinel-hunt-workbench(H11) |
Defender for Endpoint: DeviceNetworkEvents |
detection |
Validated | Systems administrators routinely use these ports for fleet maintenance |
T1098 |
Account Manipulation | persistence |
sentinel-hunt-workbench(H12) |
Sentinel: AuditLogs |
detection |
Validated | DevOps automation regularly creates and updates service principal creden… |
T1098 |
Account Manipulation | persistence |
entra-identity-workbench(HYP-FED-WILDCARD) |
Entra ID: AuditLogs |
investigation |
Validated | Evaluates offline export state; does not verify live token exchange events |
T1547.001 |
Registry Run Keys / Startup Folder | persistence |
sentinel-hunt-workbench(H05) |
Defender for Endpoint: DeviceRegistryEvents |
detection |
Validated | Approved endpoint software and updater agents regularly update run keys |
T1078.004 |
Cloud Accounts | privilege-escalation |
sentinel-hunt-workbench(H12) |
Sentinel: SigninLogs |
investigation |
Validated | Sign-ins from automated jobs cannot be distinguished from attacker use w… |
T1078.004 |
Valid Accounts: Cloud Accounts | privilege-escalation |
entra-identity-workbench(HYP-AGENT-MISMATCH) |
Entra ID: AuditLogs |
investigation |
Validated | Identifies structural over-privilege; does not prove agent tool misuse |
T1098.003 |
Additional Cloud Roles | privilege-escalation |
sentinel-hunt-workbench(H10) |
Sentinel: AuditLogs |
detection |
Validated | Eligible PIM role assignments must be separated from standing administra… |
T1098.003 |
Additional Cloud Roles | privilege-escalation |
attack-path-workbench(attackpath) |
Azure: RoleAssignments |
investigation |
Validated | Establishes structural reachability, not active adversary execution or e… |
Review Workflow & Maintenance
- Updating Mappings: Modify
catalog/attack_coverage.jsonand validate withpython3 -m cops coverage --check. - Evidence Boundaries: Do not promote an analytic from
unverifiedtovalidatedwithout specifying a reproducible test fixture invalidation_fixture. - Version Synchronization: Mappings target the pinned ATT&CK version (Enterprise v18.0). Deprecated or revoked objects are rejected by the validation gate.