MITRE ATT&CK + Your First Sigma Detection Rule (Defence)
MITRE ATT&CK is a public knowledge base of adversary tactics and techniques that blue teams use to describe behaviour in a shared language. Sigma is an open detection rule format (YAML) you can translate into SIEM queries — so your first detection engineering habit is: map a technique → write a defensive rule → test on lab logs → tune false positives. No exploit PoCs here.
Friends! ATT&CK = shared vocabulary of attacker behaviour (T-numbers). Sigma = detection rule YAML — converts into Splunk/Sentinel/Elastic. Today first defence-rule mindset: logsource, detection, false positives, ATT&CK mapping. No attack payload crafting. Own lab logs only.
मित्रांनो! ATT&CK = attacker behaviour ची shared vocabulary (T-numbers). Sigma = detection rule YAML – Splunk/Sentinel/Elastic मध्ये convert होते. आज पहिला defence rule mindset: logsource, detection, false positives, ATT&CK mapping. Attack payload crafting नाही. Own lab logs only.
मित्रों! ATT&CK = attacker behaviour की shared vocabulary (T-numbers). Sigma = detection rule YAML – Splunk/Sentinel/Elastic में convert होता है. आज पहला defence rule mindset: logsource, detection, false positives, ATT&CK mapping. Attack payload crafting नहीं. Own lab logs only.
Quick answer
ATT&CK + first Sigma rule (defence):
- Pick one technique that matches logs you actually have (for example process create).
- Read the ATT&CK technique page for data sources and defensive notes — ignore offence how-tos.
- Draft a Sigma rule: title, status, logsource, detection conditions, level, tags (
attack.txxxx). - Convert / paste into your lab SIEM or use a Sigma CLI converter offline.
- Replay known-good lab activity; measure false positives.
- Tune allow-lists carefully; document why.
- Attach a response hint: who to page, what to isolate, which IR step.
Tiny mental model:
ATT&CK technique → telemetry you own → Sigma YAML → SIEM alert → triage notes
Rule without telemetry = fiction
Rule without tuning = pager death
What do I need before this guide?
- SIEM basics.
- Optional Windows telemetry: Windows Event Logs and Sysmon.
- Comfort reading simple YAML indentation.
How do ATT&CK and Sigma fit together?
ATT&CK techniques map to Sigma YAML rules that a SIEM turns into blue-team alerts — test and tune in lab first.
ATT&CK techniques Sigma YAML rules ला map होतात जे SIEM blue-team alerts बनवतो — पहिले lab मध्ये test आणि tune करा.
ATT&CK techniques Sigma YAML rules पर map होते हैं जिन्हें SIEM blue-team alerts बनाता है — पहले lab में test और tune करो.
- Tactics — the adversary goal stage (for example Execution, Persistence) — the column headers in ATT&CK.
- Techniques / sub-techniques — how (IDs like
T1059style) — use them as tags, not as attack manuals. - Data sources — what logs you need (process monitoring, command history, network).
- Sigma — vendor-neutral detection logic focused on fields defenders already collect.
- Detection-as-code — rules in git, reviewed like application code, tested before prod.
Educational warning: this guide teaches detection. Do not use ATT&CK pages as a cookbook to attack systems. Lab generation of benign events only, on machines you own, or under written authorisation.
Real incident: SolarWinds (2020) — mapping behaviour mattered
Public reporting on the SolarWinds / SUNBURST supply-chain intrusion described stealthy follow-on activity across cloud and identity systems. Defenders worldwide used shared behavioural vocabularies (including ATT&CK-style mapping in public reporting and hunting guides) to ask: which techniques apply to our telemetry, and which detections were missing?
Takeaways (vertical):
- What happened — trusted update path abused; long dwell time in some environments.
- What went wrong (theme) — subtle identity and admin behaviours under-detected.
- Care-take — map crown-jewel abuse paths to techniques you can actually alert on.
- Care-take — third-party software integrity belongs in detection and procurement (see SBOM guide).
- Care-take — share detections as code so one analyst’s lesson helps the whole SOC.
- Bonus parallel — many IR reports now include ATT&CK heat maps for executives — useful if honest about coverage gaps.
Red Team vs Blue Team (awareness only)
Red Team — what attackers try
- Prefer techniques that look like normal admin work.
- Rotate tooling faster than signature lists.
- Test whether your detections are brittle string matches.
Blue Team — defend, detect, respond
- Cover critical techniques with layered rules (endpoint + identity + network).
- Prefer behaviour + context over single scary filename.
- Track coverage: “which techniques have any high-quality detection?”
- After incidents: add/adjust Sigma (or native) rules, not only slides.
How do I write a first Sigma rule step by step?
Step 1 — Choose a beginner-friendly technique
- Prefer something your lab already logs (Sysmon process create is ideal).
- Example theme: unusual scripting host launched by Office — tune heavily; treat as educational pattern, not a paste-into-prod nuke.
- Read official ATT&CK detection and mitigation sections only for defensive ideas.
Step 2 — Sketch fields before YAML
- Which logsource product / category / service?
- Which fields:
Image,ParentImage,CommandLine? - What is the rare condition vs everyday noise?
- What will you allow-list (update agents, security tools)?
Step 3 — Draft YAML structure (illustrative, defensive)
title: Lab - Suspicious Script Host Parent (Educational)
id: 00000000-0000-4000-8000-000000000001
status: experimental
description: Educational Sigma sketch — test only in your lab SIEM.
references:
- https://attack.mitre.org/
author: LearnFast Academy lab
date: 2026/09/29
logsource:
product: windows
category: process_creation
detection:
selection_parent:
ParentImage|endswith:
- '\\WINWORD.EXE'
- '\\EXCEL.EXE'
selection_child:
Image|endswith:
- '\\cmd.exe'
- '\\cscript.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate macros in controlled business apps (validate before prod)
level: medium
tags:
- attack.execution
- attack.t1059
This is a pattern sketch for learning structure — not a guaranteed production rule. Always test.
Step 4 — Test in lab
- On your Windows lab with Sysmon, create a benign controlled parent/child event if policy allows (for example open a test document that launches a helper you wrote) — or replay recorded sample logs.
- Confirm the rule fires.
- Perform normal Office work; list false positives.
- Tighten fields (full paths, signed parent, user context) before any wider deploy.
Step 5 — Operationalise
- Store rule in git with PR review.
- Map alert → playbook (isolate host? disable user? open IR?).
- Review weekly hits; demote noisy rules.
- Tag ATT&CK IDs so coverage dashboards stay honest.
Step 6 — Grow coverage deliberately
- Identity: rare MFA changes, new inbox rules.
- Cloud: unusual IAM failures / Disable logging APIs (high-level).
- Network: beacon-like regularity is advanced — start simpler.
- One solid rule per sprint beats fifty untested copies from the internet.
Ravindra Bagale's Tip
💡 Students import 200 Sigma rules from GitHub to "become detection engineers" — the SIEM goes red-hot. One rule, lab test, false-positive diary, then a second rule. Do not paint the ATT&CK heatmap red — leave grey where you lack telemetry. Honest coverage > pretty matrix. Stay alert!
Ravindra Bagale's Tip – मराठी
💡 Students GitHub वरून 200 Sigma rules import करून "detection engineer" व्हायचा try करतात – SIEM red hot होतो. एक rule, lab test, false positive diary, मग second rule. ATT&CK heatmap red paint नको – जेथे telemetry नाही तिथे grey ठेवा. Honest coverage > pretty matrix. ध्यान ठेवा!
Ravindra Bagale's Tip – हिंदी
💡 Students GitHub से 200 Sigma rules import करके "detection engineer" बनने की कोशिश करते हैं – SIEM red hot हो जाता है. एक rule, lab test, false positive diary, फिर second rule. ATT&CK heatmap red paint मत करो – जहाँ telemetry नहीं वहाँ grey रखो. Honest coverage > pretty matrix. ध्यान रखो!
Care-take — detection engineering hygiene
- Experimental → tested → production statuses mean something — use them.
- Every prod rule has an owner and a last-reviewed date.
- Secrets never belong inside rule sample logs committed to public repos.
- Pair preventative controls (ASR, M365 policies) with detections — do not detect-only forever.
- Purple-team lightly: ask a trusted tester to generate authorised benign artefacts that should hit your rule.
- Legal / ethics: only authorised testing.
How do I fix common ATT&CK / Sigma mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| Rule never fires | Wrong logsource / fields | Validate field names on a raw event first |
| Rule always fires | Too broad Image endswith | Add parent + path + user context; allow-list |
| Heat map “full” | Tags without telemetry | Grey out gaps; ship logs first |
| Copy-paste internet rule breaks | Product field mismatch | Convert carefully; test |
| Alert without playbook | Detection vanity | Link IR steps in the rule description |
| YAML parse errors | Indentation / tabs | Use spaces; validate with a linter |
Try it at home
Educational lab only:
- Open ATT&CK; pick one technique; write its ID and required data source in one sentence.
- Copy the YAML sketch above into a text file; rename title; keep status
experimental. - On your lab SIEM (Wazuh / Elastic / Splunk trial — whatever you run locally), convert or recreate the logic.
- Write five false-positive ideas before enabling noisy fields.
- Do not drop untested rules into a workplace SIEM without change control.
Learn it properly
Course lessons:
- What a SOC is
- Alert triage
- Signature vs anomaly IDS
- Putting it together — purple team mindset
- Indicators of compromise (IOC)
Related guides: Windows logs + Sysmon · SIEM for SOC · EDR vs AV · IR first 24 hours
Got it? ATT&CK = shared language. Sigma = portable detection YAML. Test + tune the first rule in lab — no GitHub dump. Map technique tags honestly. Defence only. Next: learn cloud IAM least privilege.
समजलं का? ATT&CK = shared language. Sigma = portable detection YAML. पहिला rule lab मध्ये test + tune — GitHub dump नको. Technique tag honestly map करा. Defence only. आता cloud IAM least privilege शिका.
समझ में आया? ATT&CK = shared language. Sigma = portable detection YAML. पहला rule lab में test + tune — GitHub dump नहीं. Technique tag honestly map करो. Defence only. आगे cloud IAM least privilege सीखो.
Frequently asked questions
What is MITRE ATT&CK?
A public knowledge base of adversary tactics and techniques used as a shared defensive language.
What is Sigma?
An open YAML detection rule format that converts into many SIEM query languages.
Should I import hundreds of rules at once?
No. One tested rule with notes beats a noisy dump that trains analysts to ignore alerts.
Do ATT&CK heat maps prove coverage?
Only if tags match real telemetry and tested detections — grey out honest gaps.
Is this for attacking systems?
No. Detection engineering on authorised labs only.
Where are deeper lessons?
SOC alert-triage and detection-minded IDS chapters on this site.