This view provides grid-based visualization of the incident, mapping the detected activities across the entire MITRE ATT&CK lifecycle.
Highlighted TTPs vs. All: By default, the matrix filters to show only the Highlighted TTPs directly associated with the incident, filtering out the noise. Analysts can toggle to All to view the complete matrix for broader context.
Attack Lifecycle Mapping: The matrix is organized by columns representing the attacker's overarching goals or Tactics (e.g., Initial Access, Credential Access, Lateral Movement).
Techniques and Sub-techniques: Beneath each Tactic, the specific Techniques (e.g., External Remote Services T1133) and Sub-techniques (e.g., Password Spraying T1110.003) utilized by the adversary are clearly flagged, giving analysts an immediate visual understanding of the attack's progression.
This view provides detailed breakdown of the specific behaviors detected, serving as an actionable guide for incident responders.
Technique Deep Dive: It lists the precise overarching techniques observed during the incident (e.g., Acquire Infrastructure T1583, Protocol Tunneling T1572). Each technique includes a Learn more link that directs analysts to the official MITRE documentation for deeper research.
Detected Sub-Techniques: Expandable rows reveal the granular sub-techniques employed (e.g., DNS T1071.004, Exfiltration Over Unencrypted Non-C2 Protocol T1048.003), pinpointing exactly how the attacker manipulated your systems or network protocols.
Recommended Mitigations: This is the most actionable area of the panel. It provides explicit, step-by-step containment and remediation strategies directly tied to the detected techniques. For example, it may recommend deploying RPZ Domain Blocks, isolating affected endpoints, or blocking specific outbound authority IPs. This bridges the gap between threat analysis and active incident response.