Fluency Security ATT&CK Coverage — Closed Cases

MITRE ATT&CK Coverage — Closed Cases

A month of closed behavior-summary clusters mapped to ATT&CK tactics and techniques, separating what the fingerprint catalog formally maps from what is still inferred from rule names.

Apex MSSP · May 1–31, 2026 · 13 active tenants · Read-only

1,043
Closed cases · 13 tenants · 30 days
~17
Techniques · 10 formal, 7 inferred
10 / 14
Tactics touched · kill-chain breadth
12 / 25
Top fingerprints mapped · 342 cases

1,043 behavior-summary clusters (riskScore ≥ 3,000) closed during May 2026 across 13 active Apex MSSP tenants, mapped to ATT&CK tactics and techniques. Formal mapping rows come from Fluency's fingerprint catalog. Inferred mapping rows are derived from rule names where the catalog is still empty. The signature catalog itself reports mapped: 0 / 81 — formal coverage exists only at the fingerprint level so far.

01 — What closed

1,043 clusters above the 3,000 risk threshold across thirteen tenants, each carrying the signatures that fired and the fingerprint that grouped them.

02 — How it maps

Twelve of the top twenty-five fingerprints carry formal ATT&CK mappings, covering a third of monthly volume. The rest are inferred from rule names and badged as such.

03 — What is missing

Four tactics were not observed at all, and signature-level mapping is still at zero. Both are addressable with a draft-then-approve pass over the catalog.

Kill chain — observed tactics in ATT&CK order

Partial formal coverage detected

12 of the top 25 fingerprints now carry formal ATT&CK mappings — covering 342 of 1,043 cases (33%). Notably, Fortigate_Webfilter_Malicious_Websites is now mapped to T1189 Drive-by Compromise (251 cases). Account-manipulation and email-collection fingerprints also have formal T1098 / T1136 / T1114 mappings. The remaining 13 high-volume fingerprints still need mapping work; this report uses inferred mappings for those rows, clearly badged.

Signature-catalog mapping gap

At the signature level the catalog still reports mapped: 0 / 81. Formal mappings exist at the fingerprint level only — driven by Fluency's internal fingerprint analysis. To make signature-level coverage non-zero, run propose_signature_mitre_mapping_candidates (a draft-only step) and then approve_signature_mitre_mapping per signature. That work persists into the catalog and removes the inference label on the next run.

Tactic volume — signature-case hits

Defense Evasion TA0005
995 · 40.6%
Initial Access TA0001
511 · 20.9%
Execution TA0002
337 · 13.8%
Persistence TA0003
109 · 4.5%
Command & Control TA0011
105 · 4.3%
Impact TA0040
99 · 4.0%
Credential Access TA0006
73 · 3.0%
Discovery TA0007
73 · 3.0%
Collection TA0009
40 · 1.6%
Lateral Movement TA0008
35 · 1.4%

Signature-case hits: each rule firing counts toward its mapped tactic. Multi-rule cases contribute to multiple tactics — totals exceed the 1,043 distinct-case denominator.

Per-tactic detail — top techniques observed

Defense Evasion TA0005

Mostly inferred
TechniqueCasesDriving signatures
T1070 Indicator Removal353AD_Scheduled_Task_Deleted (144), win_scheduled_task_deletion (144), posh_ps_remove_item_path (65)Inferred
T1562 Impair Defenses289FortiGate config changes (236), AD_Scheduled_Task_Disabled (53)Inferred
T1562.002 Disable Event Logging192AD_EventLogServiceStarted (96), Stopped (96) — 11 cases formally mappedPartly formal
T1553 Subvert Trust Controls101win_susp_codeintegrity_check_failure — 18 cases formally mappedPartly formal
T1562.001 Disable or Modify Tools60posh_ps_set_policies_to_unsecure_level — 7 cases formalPartly formal

Initial Access TA0001

Partly formal
TechniqueCasesDriving signatures
T1189 Drive-by Compromise252Fortigate_Webfilter_Malicious_WebsitesFormal fingerprint mapping
T1078.004 Cloud Accounts (Valid)200O365_AzureAD_UserLoggedInInferred
T1078 Valid Accounts (Azure)35Key_Vault_NewIP, SQL_Authentication_*_NewIPInferred
T1190 Exploit Public-Facing App (blocked)24Fortigate_Inbound_Denied_IDSInferred

Execution TA0002

Partly formal
TechniqueCasesDriving signatures
T1053.005 Scheduled Task196AD_Scheduled_Task_Created / Enabled — 24 cases formally mapped, remainder inferredPartly formal
T1047 Windows Mgmt Instrumentation141posh_ps_suspicious_gwmi — 19 cases formally mappedPartly formal

Persistence TA0003

Mostly formal
TechniqueCasesDriving signatures
T1098 Account Manipulation58O365 user updates, AzureAD auth method added (23 formal + 35 O365_User_Updated inferred)Partly formal
T1136 Create Account26O365_User_Added clustersFormal fingerprint mapping
T1098.003 Add to Group / Role25O365_AzureAD_Add_Member_To_GroupInferred

Command & Control TA0011

Partly formal
TechniqueCasesDriving signatures
T1105 Ingress Tool Transfer98posh_ps_web_request (61), posh_ps_suspicious_download (37) — 12 cases formally mappedPartly formal
T1071 Web Protocols (blocked)7Meraki_Security_Event_Detection_BlockedInferred

Remaining tactics

TacticTechniqueCasesDriving signatureBasis
Impact TA0040T1529 System Shutdown / Reboot99AD_SystemShutdownInferred
Credential Access TA0006T1110 Brute Force73win_susp_failed_logon_reasonInferred
Discovery TA0007T1083 File & Directory Discovery73posh_ps_file_and_directory_discoveryInferred
Collection TA0009T1560 Archive Collected Data29posh_ps_suspicious_extractingInferred
Collection TA0009T1114 Email Collection11O365 Exchange mailbox-permission + SendAs clusterFormal
Lateral Movement TA0008T1021.001 Remote Desktop Protocol35win_admin_rdp_login — 7 cases formally mappedPartly formal

Top techniques — ranked by signature-case volume

#TacticTechniqueDriving signatureCasesBasis
01Initial AccessT1189 Drive-by CompromiseFortigate_Webfilter_Malicious_Websites252Formal
02Initial AccessT1078.004 Cloud Accounts (Valid)O365_AzureAD_UserLoggedIn200Inferred
03ExecutionT1053.005 Scheduled Task — CreatedAD_Scheduled_Task_Created144Formal
04Defense EvasionT1070 Indicator Removal — Task DeletedAD_Scheduled_Task_Deleted144Inferred
05Defense EvasionT1070 Indicator Removal — win task delwin_scheduled_task_deletion144Inferred
06ExecutionT1047 Windows Mgmt Instrumentationposh_ps_suspicious_gwmi141Formal
07Defense EvasionT1562 Impair Defenses — admin configFortiGate_Config_Changed_By_Admin118Inferred
08Defense EvasionT1562 Impair Defenses — descriptionFortiGate_Config_Changed_Description118Inferred
09Defense EvasionT1553 Subvert Trust Controlswin_susp_codeintegrity_check_failure101Partly formal
10ImpactT1529 System Shutdown / RebootAD_SystemShutdown99Inferred
11Defense EvasionT1562.002 Disable Windows Event LoggingAD_EventLogServiceStarted96Partly formal
12Defense EvasionT1562.002 Disable Windows Event LoggingAD_EventLogServiceStopped96Partly formal
13Credential AccessT1110 Brute Forcewin_susp_failed_logon_reason73Inferred
14DiscoveryT1083 File and Directory Discoveryposh_ps_file_and_directory_discovery73Inferred
15Defense EvasionT1070.004 File Deletionposh_ps_remove_item_path65Inferred
16Command & ControlT1105 Ingress Tool Transfer — web reqposh_ps_web_request61Partly formal
17Defense EvasionT1562.001 Disable or Modify Toolsposh_ps_set_policies_to_unsecure_level60Partly formal
18Defense EvasionT1562 Impair Defenses — task disabledAD_Scheduled_Task_Disabled53Inferred
19ExecutionT1053.005 Scheduled Task — EnabledAD_Scheduled_Task_Enabled52Inferred
20Command & ControlT1105 Ingress Tool Transfer — downloadposh_ps_suspicious_download37Inferred
21Lateral MovementT1021.001 Remote Desktop Protocolwin_admin_rdp_login35Partly formal
22PersistenceT1098 Account ManipulationO365_User_Updated35Formal
23CollectionT1560 Archive Collected Dataposh_ps_suspicious_extracting29Inferred
24PersistenceT1098.003 Add to Privileged GroupO365_AzureAD_Add_Member_To_Group25Inferred
25Initial AccessT1190 Exploit Public-Facing App (blocked)Fortigate_Inbound_Denied_IDS24Inferred

Partly formal means the technique is formally mapped at the fingerprint level for a subset of cases — for example when the signature appears in a multi-rule fingerprint that carries a formal mapping. The row count is the full signature-case total; only a fraction is formally attributed.

Methodology & caveats

Source. Fluency MSSP MCP — connector 00000000-0000-0000-0000-000000000000 (Apex MSSP). Figures derived from summarize_case_metrics, summarize_case_fingerprints (top 25, with fingerprint-level mitre_attack arrays), summarize_signature_attack_coverage, and list_signature_mitre_gaps at connector scope.

Scope. 1,043 cases with status="closed" and riskScore ≥ 3,000 across 13 tenants (customer-04, customer-12, customer-06, customer-02, customer-03, customer-13, customer-07, customer-11, customer-09, customer-05, customer-01, customer-10, customer-08). Window: 2026-05-01T00:00Z → 2026-05-31 (to current time). Four Apex MSSP tenants (customer-14, customer-15, customer-16, customer-17) had no qualifying cases.

Mapping basis — mixed. 12 of the top 25 fingerprints carry formal ATT&CK mappings from Fluency's fingerprint catalog, covering ~342 cases (33% of monthly volume). Notable formal mappings: T1189 Drive-by Compromise (Fortigate webfilter), T1136 Create Account and T1098 Account Manipulation (O365 user changes), T1114 Email Collection (mailbox permission grants), T1021.001 RDP (admin RDP logins), T1047 WMI and T1053.005 Scheduled Task (posh_ps_suspicious_gwmi + AD task clusters), T1553 Subvert Trust and T1562.002 Disable Event Logging (multi-rule asset clusters). The remaining 13 fingerprints and all single-signature high-volume rules use inferred mappings from rule names. At the signature level, the catalog still reports 0 / 81 mapped — formal coverage exists at the fingerprint level only.

Counting. Tactic and technique counts are signature-case hits: a case firing multiple rules contributes once per rule's mapped tactic. Tactic-volume totals therefore exceed the 1,043 distinct-case denominator.

Recommended next step. Run propose_signature_mitre_mapping_candidates (dry-run first) to draft formal proposals for the 13 unmapped high-volume fingerprints. After analyst review, approve via approve_signature_mitre_mapping to persist into the catalog — the next monthly run will then show signature-level coverage greater than zero and remove most of the inferred badges from this report.

Known issues. The sync_signature_catalog eventwatch error is now resolved; the current run shows activity_lookup_errors: {}.

Generated 2026-05-31T07:17Z · Read-only · No Fluency mutations performed.