Home/Compliance
soc2-tsc

SOC 2 TSC. Security Controls

1 controls · cross-mapped to ATT&CK techniques
Translate between regulatory language and what attackers actually do. Each control maps to MITRE ATT&CK techniques; open a control to see those techniques and whether we hold detection coverage for them.
57
Total controls
0%
Detection coverage
0
Covered controls
57
Coverage gaps
▤ Export audit (CSV) Coverage report Self-assessment Show gaps only
▶ Check your own detection coverage

Paste the ATT&CK technique IDs you have Sigma/YARA rules for (one per line, e.g. T1059, T1190). The controls below will update to show YOUR coverage instead of ours.

Red team insight A soc2-tsc compliant org should have detection for the green-tagged techniques below. Controls showing no technique coverage are likely blind spots. Use gaps view to enumerate unmonitored attack paths.

Controls

1 shown of 1
family Confidentiality framework soc2-tsc
ATT&CK techniques this control defends against   ✓ covered by Sigma/YARA in our corpus  × = detection gap
T1003 · OS Credential Dumping T1003.001 · LSASS Memory T1003.002 · Security Account Manager T1003.003 · NTDS T1003.004 · LSA Secrets T1003.005 · Cached Domain Credentials T1003.006 · DCSync× T1003.007 · Proc Filesystem× T1003.008 · /etc/passwd and /etc/shadow T1005 · Data from Local System× T1020.001 · Traffic Duplication× T1025 · Data from Removable Media T1040 · Network Sniffing T1041 · Exfiltration Over C2 Channel T1048 · Exfiltration Over Alternative Protocol× T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.003 · Exfiltration Over Unencrypted Non-C2 Protocol× T1052 · Exfiltration Over Physical Medium× T1052.001 · Exfiltration over USB T1070 · Indicator Removal T1070.001 · Clear Windows Event Logs× T1070.002 · Clear Linux or Mac System Logs× T1070.008 · Clear Mailbox Data T1078 · Valid Accounts T1078.001 · Default Accounts T1078.003 · Local Accounts T1078.004 · Cloud Accounts T1114 · Email Collection T1114.001 · Local Email Collection× T1114.002 · Remote Email Collection T1114.003 · Email Forwarding Rule T1119 · Automated Collection T1213 · Data from Information Repositories× T1213.001 · Confluence× T1213.002 · Sharepoint× T1213.004 · Customer Relationship Management Software× T1213.005 · Messaging Applications× T1530 · Data from Cloud Storage T1548 · Abuse Elevation Control Mechanism× T1548.004 · Elevated Execution with Prompt
Equivalent controls in other frameworks  click any to see its ATT&CK technique mappings
Showing 1-1 of 1
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin