What's changed: Created SC-100 Chapter 2 (Domain 2 first-half "Security operations": Defender XDR/Sentinel (SIEM)/XDR+SIEM integration/Defender for Endpoint, Identity, Office 365, Cloud Apps; SOAR/automation rules/playbooks (Logic Apps)/threat hunting (KQL)/UEBA; centralized logging/Microsoft Purview Audit (Standard, Premium)/multicloud monitoring/retention and isolation; MITRE ATT&CK (Enterprise/Mobile/ICS)/detection coverage/incident-response workflows).
2.4MITRE ATT&CK and detection coverage
Understand evaluating threat-detection coverage using MITRE ATT&CK matrices (Enterprise, Mobile, ICS) and designing/evaluating incident-response, threat-hunting, and incident-management workflows.
To show "is our detection sufficient" with a common language rather than opinion, use the industry-standard MITRE ATT&CK. Architects map detection coverage to ATT&CK tactics/techniques, visualize gaps, and close them by priority.
2.4.1Evaluating coverage with ATT&CK
MITRE ATT&CK is a knowledge base organizing adversary tactics (goals: initial access, persistence, lateral movement, exfiltration, etc.) and techniques (how). Choose the Enterprise (IT), Mobile, or ICS (industrial control systems) matrix to match the environment. Microsoft Sentinel maps analytics rules to ATT&CK techniques and visualizes detection coverage on the matrix. Architects evaluate "which tactic stages have thin detection" and reinforce rules or data sources.
2.4.2Designing incident-response workflows
Beyond detection, design the full workflow: incident response (detect→triage→contain→eradicate→recover→lessons learned), threat hunting, and incident management. Architects define roles and procedures (who/when/what), the boundary between automation (SOAR) and human judgment, and continuous detection improvement based on ATT&CK. This makes the SOC reproducible and avoids dependence on individuals.
Cues: "evaluate detection completeness in a common language and visualize gaps" = MITRE ATT&CK (Sentinel mapping). Pick by environment: IT = Enterprise, industrial control = ICS, mobile = Mobile. "Define response procedures, roles, automation boundary" = incident-response workflow design.
Watch the mix-ups: (1) ATT&CK is a "detection-evaluation framework," not a detection product itself. (2) Do not apply only the Enterprise matrix to ICS/OT (use the ICS matrix + Defender for IoT). (3) Workflow design separates automation (SOAR) from human judgment—neither fully automatic nor fully manual.
2.4.3Section summary
- MITRE ATT&CK = evaluate detection coverage in a common tactics/techniques language; pick Enterprise/Mobile/ICS by environment
- Sentinel maps analytics rules to ATT&CK, visualizing thin stages to reinforce
- Design incident-response/hunting/management workflows with roles, procedures, and the automation boundary
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. To evaluate detection-rule completeness against industry-standard tactics/techniques and visualize coverage gaps, which is best?
Q2. When evaluating threat-detection coverage for an industrial control (OT/ICS) environment, which is most appropriate?
Q3. To avoid SOC dependence on individuals and make operations reproducible, what should be designed?
Q4. Which correctly characterizes MITRE ATT&CK?
Q5. The ATT&CK matrix shows thin detection at the "lateral movement" stage. What is the architect’s best next step?

