DEX is the AI-powered detection coverage layer for your SOC. One place to map your SIEM rules to MITRE ATT&CK, score yourself against the APT groups targeting your sector, and see which gaps to close first.
A coverage report that takes weeks by hand runs in DEX in minutes.
Five questions land on every security leader's desk. Answering any of them properly takes weeks of manual cross-referencing. DEX turns each one into an answer.
You can count your SIEM rules and list your sensors, but neither tells you which attacker techniques they actually detect.
An LLM reads the rule export, infers the data sources and use case behind each rule, and maps it to techniques and sub-techniques.
Answering takes an analyst several days of cross-referencing rules against a threat report.
Coverage is measured against the groups observed in your industry and region, with last-observed dates for each one.
Rule libraries grow through migrations and staff changes. Few teams have audited theirs.
Duplicates, dead rules and anything that can't be confidently mapped are listed individually, each with the reason.
Vendor coverage matrices are self-attested, and there is no way to verify them from inside your SOC.
SIEM rules and vendor sensors are scored on separate axes rather than averaged, showing which techniques depend entirely on a vendor.
Without a coverage baseline, the backlog is driven by the most recent incident.
Gaps are sorted by what they cost to close and how much each one unlocks, starting with work that needs no new spend.
Every answer comes out of a single run: auditable, repeatable, and ready for a board review. Re-run any time and export a shareable report.
Not a feature list. These are the things a security leader can state, and defend, once an assessment has run.
A rule count and a sensor inventory say how much you own. Coverage says how much you detect.
Establishing whether you detect a given APT group stops being several days of manual cross-referencing.
Rules and sensors are scored separately, so single-route techniques surface instead of hiding inside a healthy blended number.
Most gaps close by writing rules against telemetry already flowing in, with no procurement and no new tooling.
The backlog is ordered by coverage unlocked against effort, so next quarter runs on evidence rather than the last incident.
Because assessments repeat, a later run measures progress against the plan the earlier one produced.
Coverage percentages are the output. These four changes in how the team operates are the point.
Quarterly detection planning opens with a coverage figure and a ranked gap list, instead of whatever the most recent incident was.
The next rule an engineer writes traces to a gap the assessment found, and to the coverage it unlocks when it ships.
Whether you detect something is settled in the meeting where it's asked, with evidence rather than an estimate.
What changed since last quarter has an answer, because the previous assessment's target state is what this one is scored against.
Every Enterprise tactic and sub-technique scored
SIEM rules and vendor sensors measured separately
Re-run whenever you want and measure the movement
Coverage, adversary readiness, gaps and plan. Pick a view.
Coverage
ATT&CK coverage broken down by tactic, domain and detection route, so strong endpoint coverage can't mask a weak identity picture.
Navigator
Every technique and sub-technique in the Enterprise matrix, shaded by how well your estate covers it and by which route that coverage arrives.
APT readiness
Readiness is measured against adversaries actually observed in your industry and region, each with the date last seen. Not a generic top-ten list.
Backlog
Gaps sorted by what they cost to close and how much each one unlocks, starting with work that needs no new spend or tooling.
The hard parts of building this were mostly about refusing to flatter the result. Here's what that means in practice.
Rules that can't be confidently mapped are listed individually with the reason. A percentage over a quietly shrunk denominator is worse than none.
ATT&CK changes between releases, so the version is fixed and stated on every report. Otherwise this quarter can't be compared with the last.
Rules and sensors are scored on separate axes. Averaging them produces a comfortable number that hides the fragility worth knowing about.
Recommendations describe the capability a gap needs, with vendor-neutral alternatives alongside any extension of what you already own.
You run the extraction query in your own console and see exactly what leaves. Your rule content never trains an external model.
"Manual mapping is prone to error and exaggerated human judgement. DEX's deterministic approach maps rules accurately and gives an accurate coverage assessment, a good starting point toward continuous security posture improvement."
Murugan
Product ManagerNo. DEX gives you the extraction query. You run it in your own console and upload the export. No agent, no connector into production, and no log data leaves your environment.
Rule content is parsed regardless of the platform it came from. Bring what you have and we'll confirm your format before you commit to anything.
Expect some. Every library has them. Each one comes back listed with the reason it couldn't be confidently placed, rather than quietly dropped from the denominator.
You still get a full assessment, with rule coverage projected from your integrated telemetry and clearly labelled as projected. It shows the ceiling your data supports.
The current Enterprise release, stated on every report so results stay comparable across assessments as the matrix evolves.
That's the intended use. Assessments are self-serve, so you can run a new one whenever you want, and the target-state model means a later assessment is measured against the plan the earlier one produced. Any assessment can be exported as a shareable report.
Detection coverage and improvement recommendations are the scope. Response times, SOC capacity, alert tuning and incident-response readiness are separate workstreams, and DEX doesn't claim to measure them.
Your Security head.
No. DEX needs metadata exported from your SIEM, not raw log data and not access to the SIEM itself, so it doesn't need the review a production connector would.
Book a demo and talk to our experts. They can get you started quickly with credits.
Book a working session and we'll run DEX against your stack: ATT&CK coverage, APT readiness, and the first slice of your backlog.
Positka specializes in high-end technology solutions to help businesses improve their IT infrastructure with advanced Security Protocols, excellence in Analytics, Streamlined IT Operations, & around-the-clock Managed services.
Copyright Positka © 2024. All Rights Reserved.
Positka uses cookies to provide necessary site functionality and improved experience. By using our website, you agree to our privacy policy.