ATT&CK library

Every technique, with the rule that catches it

Not another glossary. Each page shows what a real attack looks like in your telemetry, the exact Sigma and Wazuh detections, and a live Tyrian range where you can run it and watch the rule fire.

Credential AccessDefense EvasionExecutionImpactInitial AccessLateral MovementPersistencePrivilege Escalation

The rules are free. Take them.

Every detection here ships in the open-source Tyrian Detection Pack: 67 Sigma rules across 64 ATT&CK techniques, Windows and Linux, compiled to Wazuh, Splunk and Sentinel, with an ATT&CK Navigator layer and a command that fires each one. MIT licensed. Clone it, drop it into your SIEM, then prove it works on a real range.

Get the Detection Pack