Map security alerts to MITRE ATT&CK techniques
Detection and reporting teams tag alerts with ATT&CK technique ids to track coverage. It is slow, and easy to do inconsistently. Apex Flash can propose technique mappings with reasons, and you check each id against the official matrix.
Set it up
- Export a batch of alert names with one line of description each.
- Send them to apex-flash with the mapping prompt.
- Collect the proposed ids, names and confidence levels.
- Look up every id on attack.mitre.org and compare the name.
- Reject any id that does not exist or has been renamed.
- Store the confirmed mapping in your detection catalogue.
Authorisation boundary
Map alerts from your own environment or lab. ATT&CK is a knowledge base of adversary behaviour for defence; this workflow is about labelling what you detected, not planning attacks.
Sanitised sample input
1. Encoded PowerShell launched by WINWORD.EXE
2. Scheduled task created by non-admin user
3. 40 failed logons across 40 accounts from one IP, one password tried
4. Non-system process opened a handle to lsass.exe
5. Successful login for a dormant account from a new countryThe prompt and the call
Map each alert to the most likely MITRE ATT&CK Enterprise technique or sub-technique.
For each give: technique id, technique name, tactic, confidence (low/medium/high), and one sentence of reasoning that quotes the alert text.
If an alert is ambiguous, give two candidates. If you are not sure of an id, say so instead of guessing. Do not map alerts that lack enough information.
<alerts>
...list...
</alerts>import os
from openai import OpenAI
client = OpenAI(base_url="https://wildwestapi.com/v1",
api_key=os.environ["WILDWEST_API_KEY"])
resp = client.chat.completions.create(
model="apex-flash",
temperature=0.2,
messages=[
{"role": "system", "content": "You map alerts to MITRE ATT&CK carefully."},
{"role": "user", "content": open("attack_prompt.txt", encoding="utf-8").read()},
],
)
print(resp.choices[0].message.content)Keys look like sk-ww-...; keep yours in the WILDWEST_API_KEY environment variable, never in the script. Calls to /v1/chat/completions use the OpenAI format, billing is pay-as-you-go, and prompts are not retained on /v1.
Expected answers to compare with
For these five, sensible mappings are below. Each id was checked on attack.mitre.org.
- Encoded PowerShell from an Office process: T1059.001 PowerShell (Execution), possibly with T1566.001 Spearphishing Attachment as the entry route.
- Scheduled task creation: T1053.005 Scheduled Task.
- One password across many accounts: T1110.003 Password Spraying (Credential Access).
- Handle to lsass.exe: T1003.001 LSASS Memory.
- Login to a dormant account: T1078 Valid Accounts, which spans several tactics.
What to check
- Technique ids exist and the names match. Models sometimes return retired ids or blend two techniques.
- Sub-technique choice. Ask for the parent technique too if you are not sure.
- Reasoning quotes the alert. A mapping from the alert title alone is weak.
- ATT&CK is versioned. Record which version your catalogue uses.
Both apex-flash and glm-5.3-flash-cyber are security-tuned models with a 1M-token context window, tool calling and vision. They are not uncensored models, and they are meant for defensive and authorised work like this. A mapped alert is not a detected technique; mapping says what the alert might represent, not how well you cover it.
Where this fits
Use Sigma rules with attack.* tags, and the same mapping in a pentest report. See detection engineering and DFIR.
FAQ
Will it always return real technique ids?
No. Verify every id on attack.mitre.org. Ask it to say when unsure.
Does it cover ICS or mobile matrices?
Name the matrix in the prompt. These examples use Enterprise only.
Can it score my coverage?
It can summarise a list you give it, but coverage depends on testing your detections, not on labels.