Microsoft Defender for Cloud

MITRE ATT&CK coverage

Snapshot of the MITRE ATT&CK coverage matrix for Microsoft Defender for Cloud security alerts maintained by pisinger.github.io. Data sourced from Microsoft Learn. Shows which Defender plans cover which MITRE tactics, based on documented and observed alerts. Excludes deprecated alerts. Tactics marked with * are Microsoft-specific, not standard MITRE enterprise tactics. Disclaimer & sources.

🛡️ Alerts
Loading data...
0 Defender plans
0 MITRE tactics
0 covered cells
0 total cells

Disclaimer & sources

This MITRE ATT&CK coverage matrix is derived from the documented and observed Microsoft Defender for Cloud security alerts. It shows which Defender plans have alerts mapped to which MITRE tactics.

Coverage does not imply completeness. A plan may detect techniques under a tactic even if no alert is explicitly mapped to it in the public documentation. This matrix reflects only the documented alert-to-tactic mappings from Microsoft Learn plus real observed alerts.

Alerts marked as "archive" were sourced from deprecated/archived pages and may no longer be actively documented by Microsoft. They are included for reference.

Deprecated alerts are excluded from this matrix.

Non-standard tactics: "Exploitation" and "Probing" are Microsoft-specific kill chain stages, not official MITRE ATT&CK enterprise tactics. They are marked with an asterisk (*) in the matrix. "Pre-Attack" is from the MITRE PRE-ATT&CK matrix.

Sources

Non-official reference maintained by pisinger.github.io.