A month of closed behavior-summary clusters mapped to ATT&CK tactics and techniques, separating what the fingerprint catalog formally maps from what is still inferred from rule names.
1,043 behavior-summary clusters (riskScore ≥ 3,000) closed during May 2026 across 13 active Apex MSSP tenants, mapped to ATT&CK tactics and techniques. Formal mapping rows come from Fluency's fingerprint catalog. Inferred mapping rows are derived from rule names where the catalog is still empty. The signature catalog itself reports mapped: 0 / 81 — formal coverage exists only at the fingerprint level so far.
1,043 clusters above the 3,000 risk threshold across thirteen tenants, each carrying the signatures that fired and the fingerprint that grouped them.
Twelve of the top twenty-five fingerprints carry formal ATT&CK mappings, covering a third of monthly volume. The rest are inferred from rule names and badged as such.
Four tactics were not observed at all, and signature-level mapping is still at zero. Both are addressable with a draft-then-approve pass over the catalog.
12 of the top 25 fingerprints now carry formal ATT&CK mappings — covering 342 of 1,043 cases (33%). Notably, Fortigate_Webfilter_Malicious_Websites is now mapped to T1189 Drive-by Compromise (251 cases). Account-manipulation and email-collection fingerprints also have formal T1098 / T1136 / T1114 mappings. The remaining 13 high-volume fingerprints still need mapping work; this report uses inferred mappings for those rows, clearly badged.
At the signature level the catalog still reports mapped: 0 / 81. Formal mappings exist at the fingerprint level only — driven by Fluency's internal fingerprint analysis. To make signature-level coverage non-zero, run propose_signature_mitre_mapping_candidates (a draft-only step) and then approve_signature_mitre_mapping per signature. That work persists into the catalog and removes the inference label on the next run.
Signature-case hits: each rule firing counts toward its mapped tactic. Multi-rule cases contribute to multiple tactics — totals exceed the 1,043 distinct-case denominator.
| Technique | Cases | Driving signatures |
|---|---|---|
| T1070 Indicator Removal | 353 | AD_Scheduled_Task_Deleted (144), win_scheduled_task_deletion (144), posh_ps_remove_item_path (65)Inferred |
| T1562 Impair Defenses | 289 | FortiGate config changes (236), AD_Scheduled_Task_Disabled (53)Inferred |
| T1562.002 Disable Event Logging | 192 | AD_EventLogServiceStarted (96), Stopped (96) — 11 cases formally mappedPartly formal |
| T1553 Subvert Trust Controls | 101 | win_susp_codeintegrity_check_failure — 18 cases formally mappedPartly formal |
| T1562.001 Disable or Modify Tools | 60 | posh_ps_set_policies_to_unsecure_level — 7 cases formalPartly formal |
| Technique | Cases | Driving signatures |
|---|---|---|
| T1189 Drive-by Compromise | 252 | Fortigate_Webfilter_Malicious_WebsitesFormal fingerprint mapping |
| T1078.004 Cloud Accounts (Valid) | 200 | O365_AzureAD_UserLoggedInInferred |
| T1078 Valid Accounts (Azure) | 35 | Key_Vault_NewIP, SQL_Authentication_*_NewIPInferred |
| T1190 Exploit Public-Facing App (blocked) | 24 | Fortigate_Inbound_Denied_IDSInferred |
| Technique | Cases | Driving signatures |
|---|---|---|
| T1053.005 Scheduled Task | 196 | AD_Scheduled_Task_Created / Enabled — 24 cases formally mapped, remainder inferredPartly formal |
| T1047 Windows Mgmt Instrumentation | 141 | posh_ps_suspicious_gwmi — 19 cases formally mappedPartly formal |
| Technique | Cases | Driving signatures |
|---|---|---|
| T1098 Account Manipulation | 58 | O365 user updates, AzureAD auth method added (23 formal + 35 O365_User_Updated inferred)Partly formal |
| T1136 Create Account | 26 | O365_User_Added clustersFormal fingerprint mapping |
| T1098.003 Add to Group / Role | 25 | O365_AzureAD_Add_Member_To_GroupInferred |
| Technique | Cases | Driving signatures |
|---|---|---|
| T1105 Ingress Tool Transfer | 98 | posh_ps_web_request (61), posh_ps_suspicious_download (37) — 12 cases formally mappedPartly formal |
| T1071 Web Protocols (blocked) | 7 | Meraki_Security_Event_Detection_BlockedInferred |
| Tactic | Technique | Cases | Driving signature | Basis |
|---|---|---|---|---|
| Impact TA0040 | T1529 System Shutdown / Reboot | 99 | AD_SystemShutdown | Inferred |
| Credential Access TA0006 | T1110 Brute Force | 73 | win_susp_failed_logon_reason | Inferred |
| Discovery TA0007 | T1083 File & Directory Discovery | 73 | posh_ps_file_and_directory_discovery | Inferred |
| Collection TA0009 | T1560 Archive Collected Data | 29 | posh_ps_suspicious_extracting | Inferred |
| Collection TA0009 | T1114 Email Collection | 11 | O365 Exchange mailbox-permission + SendAs cluster | Formal |
| Lateral Movement TA0008 | T1021.001 Remote Desktop Protocol | 35 | win_admin_rdp_login — 7 cases formally mapped | Partly formal |
| # | Tactic | Technique | Driving signature | Cases | Basis |
|---|---|---|---|---|---|
| 01 | Initial Access | T1189 Drive-by Compromise | Fortigate_Webfilter_Malicious_Websites | 252 | Formal |
| 02 | Initial Access | T1078.004 Cloud Accounts (Valid) | O365_AzureAD_UserLoggedIn | 200 | Inferred |
| 03 | Execution | T1053.005 Scheduled Task — Created | AD_Scheduled_Task_Created | 144 | Formal |
| 04 | Defense Evasion | T1070 Indicator Removal — Task Deleted | AD_Scheduled_Task_Deleted | 144 | Inferred |
| 05 | Defense Evasion | T1070 Indicator Removal — win task del | win_scheduled_task_deletion | 144 | Inferred |
| 06 | Execution | T1047 Windows Mgmt Instrumentation | posh_ps_suspicious_gwmi | 141 | Formal |
| 07 | Defense Evasion | T1562 Impair Defenses — admin config | FortiGate_Config_Changed_By_Admin | 118 | Inferred |
| 08 | Defense Evasion | T1562 Impair Defenses — description | FortiGate_Config_Changed_Description | 118 | Inferred |
| 09 | Defense Evasion | T1553 Subvert Trust Controls | win_susp_codeintegrity_check_failure | 101 | Partly formal |
| 10 | Impact | T1529 System Shutdown / Reboot | AD_SystemShutdown | 99 | Inferred |
| 11 | Defense Evasion | T1562.002 Disable Windows Event Logging | AD_EventLogServiceStarted | 96 | Partly formal |
| 12 | Defense Evasion | T1562.002 Disable Windows Event Logging | AD_EventLogServiceStopped | 96 | Partly formal |
| 13 | Credential Access | T1110 Brute Force | win_susp_failed_logon_reason | 73 | Inferred |
| 14 | Discovery | T1083 File and Directory Discovery | posh_ps_file_and_directory_discovery | 73 | Inferred |
| 15 | Defense Evasion | T1070.004 File Deletion | posh_ps_remove_item_path | 65 | Inferred |
| 16 | Command & Control | T1105 Ingress Tool Transfer — web req | posh_ps_web_request | 61 | Partly formal |
| 17 | Defense Evasion | T1562.001 Disable or Modify Tools | posh_ps_set_policies_to_unsecure_level | 60 | Partly formal |
| 18 | Defense Evasion | T1562 Impair Defenses — task disabled | AD_Scheduled_Task_Disabled | 53 | Inferred |
| 19 | Execution | T1053.005 Scheduled Task — Enabled | AD_Scheduled_Task_Enabled | 52 | Inferred |
| 20 | Command & Control | T1105 Ingress Tool Transfer — download | posh_ps_suspicious_download | 37 | Inferred |
| 21 | Lateral Movement | T1021.001 Remote Desktop Protocol | win_admin_rdp_login | 35 | Partly formal |
| 22 | Persistence | T1098 Account Manipulation | O365_User_Updated | 35 | Formal |
| 23 | Collection | T1560 Archive Collected Data | posh_ps_suspicious_extracting | 29 | Inferred |
| 24 | Persistence | T1098.003 Add to Privileged Group | O365_AzureAD_Add_Member_To_Group | 25 | Inferred |
| 25 | Initial Access | T1190 Exploit Public-Facing App (blocked) | Fortigate_Inbound_Denied_IDS | 24 | Inferred |
Partly formal means the technique is formally mapped at the fingerprint level for a subset of cases — for example when the signature appears in a multi-rule fingerprint that carries a formal mapping. The row count is the full signature-case total; only a fraction is formally attributed.
Source. Fluency MSSP MCP — connector 00000000-0000-0000-0000-000000000000 (Apex MSSP). Figures derived from summarize_case_metrics, summarize_case_fingerprints (top 25, with fingerprint-level mitre_attack arrays), summarize_signature_attack_coverage, and list_signature_mitre_gaps at connector scope.
Scope. 1,043 cases with status="closed" and riskScore ≥ 3,000 across 13 tenants (customer-04, customer-12, customer-06, customer-02, customer-03, customer-13, customer-07, customer-11, customer-09, customer-05, customer-01, customer-10, customer-08). Window: 2026-05-01T00:00Z → 2026-05-31 (to current time). Four Apex MSSP tenants (customer-14, customer-15, customer-16, customer-17) had no qualifying cases.
Mapping basis — mixed. 12 of the top 25 fingerprints carry formal ATT&CK mappings from Fluency's fingerprint catalog, covering ~342 cases (33% of monthly volume). Notable formal mappings: T1189 Drive-by Compromise (Fortigate webfilter), T1136 Create Account and T1098 Account Manipulation (O365 user changes), T1114 Email Collection (mailbox permission grants), T1021.001 RDP (admin RDP logins), T1047 WMI and T1053.005 Scheduled Task (posh_ps_suspicious_gwmi + AD task clusters), T1553 Subvert Trust and T1562.002 Disable Event Logging (multi-rule asset clusters). The remaining 13 fingerprints and all single-signature high-volume rules use inferred mappings from rule names. At the signature level, the catalog still reports 0 / 81 mapped — formal coverage exists at the fingerprint level only.
Counting. Tactic and technique counts are signature-case hits: a case firing multiple rules contributes once per rule's mapped tactic. Tactic-volume totals therefore exceed the 1,043 distinct-case denominator.
Recommended next step. Run propose_signature_mitre_mapping_candidates (dry-run first) to draft formal proposals for the 13 unmapped high-volume fingerprints. After analyst review, approve via approve_signature_mitre_mapping to persist into the catalog — the next monthly run will then show signature-level coverage greater than zero and remove most of the inferred badges from this report.
Known issues. The sync_signature_catalog eventwatch error is now resolved; the current run shows activity_lookup_errors: {}.
Generated 2026-05-31T07:17Z · Read-only · No Fluency mutations performed.