AXERA
Detection catalog

Eighteen detectors. One incident.

Every detector below is process-attributed, so an incident names the workload, the binary and the destination. Related signals are correlated into one incident and placed on the MITRE ATT&CK attack lifecycle.

18detectors16with an explicit ATT&CK technique2behavioural baselines
Catalog

What each detector catches

The list mirrors the detectors shipped in the product. Names are the ones you will see on an incident.

DetectorWhat it catchesATT&CKTactic
IP reputationA workload connects to an address on a threat-intelligence blocklist.T1071Command and control
DNS threatA workload resolves a domain flagged as malicious.T1071.004Command and control
Lateral movementA workload starts talking to peers in other namespaces it never reached before.T1021Lateral movement
BeaconingRegular, timed callbacks from one workload to one external host.T1071Command and control
Behavioural anomalyA workload's traffic drifts from the baseline Axera learned for it.baselineBaseline deviation
Fan-out reconnaissanceOne workload probes many peers or ports in a short window.T1046Discovery
Egress volumeOutbound volume from a workload spikes far above its norm.baselineBaseline deviation
Unexpected processA binary the workload has never run before opens network connections.T1059Execution
Denied-connection sprayBursts of connection attempts that policy keeps denying.T1046Discovery
Mesh identity denyThe service mesh denies a workload identity that should not be calling.T1078Privilege escalation
Process port scanA single process sweeps ports across peers.T1046Discovery
Runtime execAn interactive shell or privilege escalation inside a running container.T1548Privilege escalation
DNS tunnellingData smuggled inside DNS queries and answers.T1048.003Exfiltration
Cloud metadata abuseA workload calls the cloud instance metadata API to harvest credentials.T1552.005Credential access
Peer egress anomalyA workload reaches an external destination none of its peers use.T1048Exfiltration
TLS fingerprintA TLS client fingerprint that matches known attacker tooling.T1071Command and control
Secret readA process reads mounted secrets or credential files it has no business touching.T1552.001Credential access
Control-plane abuseValid credentials used for suspicious Kubernetes API actions.T1078Privilege escalation

Two detectors (behavioural anomaly, egress volume) learn a per-workload baseline instead of matching a fixed technique; they surface as tactic-level context on the incident.

MITRE ATT&CK coverage

Coverage across the attack lifecycle

Grouped by the ATT&CK tactic each detector maps to, so you can see where coverage is dense and where it is thin.

DiscoveryFan-out reconnaissance · Denied-connection spray · Process port scan
ExecutionUnexpected process
Privilege escalationMesh identity deny · Runtime exec · Control-plane abuse
Credential accessCloud metadata abuse · Secret read
Lateral movementLateral movement
Command and controlIP reputation · DNS threat · Beaconing · TLS fingerprint
ExfiltrationDNS tunnelling · Peer egress anomaly
Baseline deviationBehavioural anomaly · Egress volume

See Axera on your own clusters.

A 20-minute lab walkthrough with an engineer, or a proof of concept on clusters you control. The PoC runs entirely inside your perimeter.