Axera
Detection catalog

Detectors, mapped to ATT&CK.

Every Axera detector is process-attributed and mapped to MITRE ATT&CK, so each incident carries who, from which binary, to what — and where it sits in the kill-chain.

Detect

What Axera detects

Process-attributed incidents — who, from which binary, to what

MITRE ATT&CK kill-chain fusion across signals

Real DNS telemetry detection

Mesh & identity threat detection

Denied-connection spray and scanning

Runtime exec / privilege-escalation detection

Threat-intel expansion and adaptive thresholds

Crown-jewel asset registry to prioritize what matters

MITRE ATT&CK coverage

Coverage across the kill-chain

Every incident is mapped to techniques, so you can see coverage at a glance.

ReconnaissanceDenied-connection spray, port and service scanning
Initial AccessAnomalous ingress and first-seen external peers
ExecutionRuntime exec from unexpected binaries
PersistenceNew long-lived listeners and workloads
Privilege EscalationRuntime privilege-escalation attempts
Defense EvasionMesh-identity spoofing and policy bypass
DiscoveryEast-west scanning and denied-spray fan-out
Lateral MovementCross-namespace pivots the kill-chain fuses
Exfiltration / ImpactSuspicious egress and DNS to flagged destinations

See how Axera responds →