Detection catalog
Detectors, mapped to ATT&CK.
Every Axera detector is process-attributed and mapped to MITRE ATT&CK, so each incident carries who, from which binary, to what — and where it sits in the kill-chain.
Detect
What Axera detects
Process-attributed incidents — who, from which binary, to what
MITRE ATT&CK kill-chain fusion across signals
Real DNS telemetry detection
Mesh & identity threat detection
Denied-connection spray and scanning
Runtime exec / privilege-escalation detection
Threat-intel expansion and adaptive thresholds
Crown-jewel asset registry to prioritize what matters
MITRE ATT&CK coverage
Coverage across the kill-chain
Every incident is mapped to techniques, so you can see coverage at a glance.
ReconnaissanceDenied-connection spray, port and service scanning
Initial AccessAnomalous ingress and first-seen external peers
ExecutionRuntime exec from unexpected binaries
PersistenceNew long-lived listeners and workloads
Privilege EscalationRuntime privilege-escalation attempts
Defense EvasionMesh-identity spoofing and policy bypass
DiscoveryEast-west scanning and denied-spray fan-out
Lateral MovementCross-namespace pivots the kill-chain fuses
Exfiltration / ImpactSuspicious egress and DNS to flagged destinations