This thesis project maps a subset of rules from a corporate SIEM system to tactics and techniques in the MITRE ATT&CK framework. This process identifies the tactics and techniques associated with each rule to provide more context to security incidents. The project also develops a query for the Splunk SIEM to evaluate the coverage of rules against techniques in the framework. Understanding coverage is important for improving detection capabilities and identifying security gaps. The mapping and query help analysts better understand alerts and enhance the SIEM's detection abilities in line with the MITRE ATT&CK framework.
Related topics: