Detection catalog
Eighteen detectors. One incident.
Every detector below is process-attributed, so an incident names the workload, the binary and the destination. Related signals are correlated into one incident and placed on the MITRE ATT&CK attack lifecycle.
18detectors16with an explicit ATT&CK technique2behavioural baselines
Catalog
What each detector catches
The list mirrors the detectors shipped in the product. Names are the ones you will see on an incident.
| Detector | What it catches | ATT&CK | Tactic |
|---|---|---|---|
| IP reputation | A workload connects to an address on a threat-intelligence blocklist. | T1071 | Command and control |
| DNS threat | A workload resolves a domain flagged as malicious. | T1071.004 | Command and control |
| Lateral movement | A workload starts talking to peers in other namespaces it never reached before. | T1021 | Lateral movement |
| Beaconing | Regular, timed callbacks from one workload to one external host. | T1071 | Command and control |
| Behavioural anomaly | A workload's traffic drifts from the baseline Axera learned for it. | baseline | Baseline deviation |
| Fan-out reconnaissance | One workload probes many peers or ports in a short window. | T1046 | Discovery |
| Egress volume | Outbound volume from a workload spikes far above its norm. | baseline | Baseline deviation |
| Unexpected process | A binary the workload has never run before opens network connections. | T1059 | Execution |
| Denied-connection spray | Bursts of connection attempts that policy keeps denying. | T1046 | Discovery |
| Mesh identity deny | The service mesh denies a workload identity that should not be calling. | T1078 | Privilege escalation |
| Process port scan | A single process sweeps ports across peers. | T1046 | Discovery |
| Runtime exec | An interactive shell or privilege escalation inside a running container. | T1548 | Privilege escalation |
| DNS tunnelling | Data smuggled inside DNS queries and answers. | T1048.003 | Exfiltration |
| Cloud metadata abuse | A workload calls the cloud instance metadata API to harvest credentials. | T1552.005 | Credential access |
| Peer egress anomaly | A workload reaches an external destination none of its peers use. | T1048 | Exfiltration |
| TLS fingerprint | A TLS client fingerprint that matches known attacker tooling. | T1071 | Command and control |
| Secret read | A process reads mounted secrets or credential files it has no business touching. | T1552.001 | Credential access |
| Control-plane abuse | Valid credentials used for suspicious Kubernetes API actions. | T1078 | Privilege escalation |
Two detectors (behavioural anomaly, egress volume) learn a per-workload baseline instead of matching a fixed technique; they surface as tactic-level context on the incident.
MITRE ATT&CK coverage
Coverage across the attack lifecycle
Grouped by the ATT&CK tactic each detector maps to, so you can see where coverage is dense and where it is thin.
DiscoveryFan-out reconnaissance · Denied-connection spray · Process port scan
ExecutionUnexpected process
Privilege escalationMesh identity deny · Runtime exec · Control-plane abuse
Credential accessCloud metadata abuse · Secret read
Lateral movementLateral movement
Command and controlIP reputation · DNS threat · Beaconing · TLS fingerprint
ExfiltrationDNS tunnelling · Peer egress anomaly
Baseline deviationBehavioural anomaly · Egress volume
See Axera on your own clusters.
A 20-minute lab walkthrough with an engineer, or a proof of concept on clusters you control. The PoC runs entirely inside your perimeter.