list_by_mitre_tactic
Find detection rules mapped to a specific MITRE ATT&CK tactic. Filter by source and limit results to prioritize your investigation.
Instructions
List all detections mapped to a MITRE ATT&CK tactic (e.g., execution, persistence, defense_evasion, credential_access).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum results (default: 50) | |
| source | No | Optional source filter: sigma, splunk_escu, elastic, kql | |
| tactic | Yes | MITRE tactic name (e.g., execution, persistence, defense_evasion, lateral_movement) |