Analyze product coverage with MITRE Explorer

Prev Next

The MITRE Explorer provides an interactive Trellix Detection Matrix based on the MITRE ATT&CK framework. You can use it to visualize your organization's detection coverage across your portfolio of Trellix products and analyze how active threats use specific techniques.

This matrix helps you understand which attack techniques are covered by your selected products and identify potential gaps in your defenses.

Visualize your product detection coverage

You can filter the matrix to see which ATT&CK techniques are covered by the detection rules in your specific portfolio of Trellix products.

  1. Navigate to MITRE Explorer from the main menu.

  2. Select one or more Trellix products, for example. ENS, EDR, Helix, Email EX/ETP to see which techniques are covered by your current portfolio.

  3. Choose one or more Trellix products from the list, such as EDR, ENS, or Helix.

  4. The ATT&CK matrix updates with color-coding. The colors indicate how many of your selected products provide detection rules for a specific technique:

    • Dark Green (+3): Three or more products provide coverage.

    • Medium Green (2): Two products provide coverage.

    • Light Green (1): One product provides coverage.

    • Gray (0): No detection rules are associated with this technique from your selected products.

  5. Click any technique on the matrix to see which products are providing coverage and how many rules are available. A detail pane appears that shows each product and the number of detection rules associated with that technique (for example, "EDR: 21 rules" or "Helix: 12 rules").

  6. Click Add Filters to prioritize your threat coverage by mapping your product coverage.

Investigate your protection for a specific technique

MITRE Explorer shows which products are providing protection and the number of detection rules they have.

  1. From the Trellix Detection Matrix, click on a specific technique (For example, "Exploitation for Client Execution"). A detail pane is displayed on the right side of the screen.

  2. By selecting a specific MITRE technique, you can view a detailed breakdown of detection rules available for each product. You can view:

    • Technique name and description: A detailed definition of the technique as defined by MITRE.

    • Tactic: The MITRE ATT&CK tactic this technique belongs to (For example, Execution).

    • Technique ID: The official ID for the technique (For example, T1203).

    • Rule Count Per Product: A complete list of all Trellix products that have detection rules for this technique, along with the specific number of rules for each product.

    • Associated Campaigns: A list of active threat campaigns and threat profiles in Trellix Insights that use this technique. You can click a campaign name to navigate directly to its Campaign Details page for further investigation.

    Note

    The pane displays only the product and the total rule count, not the specific detection rules.

  3. Locate the Command Lines details below the matrix. The Command Lines widget displays actionable data about the attack processes used by threat actors.

    Note

    To view the Command Lines widget, you must first apply a filter or select a product from the Select Products dropdown menu within the MITRE Matrix.

    The widget includes the following details:

    • Command Line: The specific command string and options executed by a program, for example, cmd.exe /c wbadmindelete catalog -quiet).

    • Technique ID: The associated MITRE ATT&CK IDs, for example, T1059.003, T1490.

    • Tools: The utilities identified in the command execution, for example, VSSAdmin, wbadmin.

    • Description: A brief explanation of the command’s role within the program execution.

    • Sort the table by the Command Lines and Tools columns to better organize the identified attack processes.

Threat hunt with enhanced filters

The matrix shows only the techniques associated with the threat that you filtered, allowing you to see how your products defend against their specific tactics.

  1. On the MITRE Explorer page, click Add Filters.

  2. Select your criteria. You can filter the matrix by:

    • Campaigns

    • Threat Actors

    • Threat Types (For example, Ransomware)

    • Tools

    • Severity

    • Prevalent Country

    • Prevalent Sector

  3. Click Apply.