SpectraStrike Documentation

Operational, architecture, SDK, and integration guidance

MITRE ATT&CK Telemetry Mapping (Sprint 32)

This mapping ties SpectraStrike telemetry normalization and federation payloads to ATT&CK-aligned attributes used by downstream analytics.

Telemetry Contract Alignment

References:

Tool/Event to ATT&CK Mapping Baseline

Tool/Event Pattern ATT&CK Technique(s) ATT&CK Tactic(s) Mapping Source
nmap_scan_completed / network probing T1595 Active Scanning TA0043 Reconnaissance Event defaults and wrapper attributes
metasploit_exploit_completed T1059 Command and Scripting Interpreter (context dependent) TA0002 Execution Wrapper event metadata + finding normalization
sliver_command_completed T1105 Ingress Tool Transfer / operator command channel context TA0011 Command and Control Sliver wrapper telemetry attributes
mythic_task_completed T1059 Command and Scripting Interpreter (task dependent) TA0002 Execution Mythic wrapper task telemetry attributes
Generic PROCESS_ANOMALY federation event technique/tactic passed in attributes or fallback attribute-driven vectorvue/rabbitmq_bridge.py normalization

Quality and Integrity Constraints

Scope Notes