Basyrix SOC Response Atlas by Basyrix

Docs

SOC Response Atlas has no backend and no database. Every technique's data is generated at build time from a YAML source pack into plain static JSON and Markdown files under /api. The frontend calls the exact same files an external caller can curl directly.

Available files, per technique

Example

curl https://atlas.basyrix.com/api/recommendations/T1078.json
curl https://atlas.basyrix.com/api/confluence/T1078.md

Using the Confluence export

Each technique's Confluence Export tab has Copy / View / Download buttons for the generated Markdown. Paste it into a Confluence page — headings, tables, and the KQL code block carry over cleanly. Basyrix Pro will later push and update the page directly via the Confluence API instead of copy/paste.

What's covered right now

The matrix is the real MITRE ATT&CK Enterprise catalog -- all 15 tactics, 222 top-level techniques, imported directly from MITRE's own STIX data (scripts/import-mitre.ts). Every technique has a recommendation pack, but at two honest depths, shown as different tile colors:

Basyrix SecOps Platform (paid, later)

Live Sentinel/Defender XDR enrichment, direct Confluence push, ServiceNow ticket generation, Torq SOAR workflow integration, MISP/Cyble threat intel, Fortra vulnerability context, tenant-aware private recommendation packs, team workspaces, and response coverage dashboards. The free map here stays free — the paid platform adds live context, automation, and scale on top of it.