Turn MITRE ATT&CK into SOC-ready response guidance.
Search any ATT&CK technique and get D3FEND mappings, investigation steps, containment actions, KQL, and Confluence-ready runbook content.
What it does
For a given ATT&CK technique, SOC Response Atlas gives you the D3FEND defensive mapping, concrete investigation steps for Microsoft-centric environments, ready-to-run KQL, and a Confluence-ready runbook block โ all served as plain static JSON and Markdown files, no server required.
The core loop
ATT&CK technique → D3FEND mapping → SOC recommendation → KQL → Confluence export
Example: T1078 โ Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts. Start here to see the full response pack, D3FEND mappings, and static API output for this technique.
Open T1078 →Free, forever
- Public technique pages with D3FEND mappings
- Practical, Microsoft-focused investigation steps
- KQL / SPL / ES|QL query snippets
- Confluence-ready Markdown export
- A static JSON API you can curl directly
- No login, no rate limits, no paywall on the map
Want this tailored to your tenant, pushed straight to Confluence, or wired into Sentinel and ServiceNow? That's the Basyrix SecOps Platform โ the free map here always stays free.