Basyrix SOC Response Atlas by Basyrix

Docs

SOC Response Atlas has no backend and no database. Every technique's data is generated at build time from a YAML source pack into plain static JSON and Markdown files under /api. The frontend calls the exact same files an external caller can curl directly.

Available files, per technique

Example

curl https://atlas.basyrix.com/api/recommendations/T1078.json
curl https://atlas.basyrix.com/api/confluence/T1078.md

Using the Confluence export

Each technique's Confluence Export tab has Copy / View / Download buttons for the generated Markdown. Paste it into a Confluence page — headings, tables, and the KQL code block carry over cleanly. Basyrix Pro will later push and update the page directly via the Confluence API instead of copy/paste.

What's covered right now

The matrix is the real MITRE ATT&CK Enterprise catalog -- all 15 tactics, 222 top-level techniques, imported directly from MITRE's own STIX data (scripts/import-mitre.ts). Every technique has a recommendation pack, but at two honest depths, shown as different tile colors:

KQL/ES|QL isn't gated behind that split: 157 packs have real Sentinel detection rules and 161 have real Elastic detection rules (from Bell Integration's own baseline library, Microsoft's official Azure-Sentinel Detections, and Elastic's official detection-rules repo), spanning both purple and amber tiers. 38 techniques had no real match in either source and kept a generic placeholder query.

Basyrix SecOps Platform (paid, later)

Live Sentinel/Defender XDR enrichment, direct Confluence push, ServiceNow ticket generation, Torq SOAR workflow integration, MISP/Cyble threat intel, Fortra vulnerability context, tenant-aware private recommendation packs, team workspaces, and response coverage dashboards. The free map here stays free — the paid platform adds live context, automation, and scale on top of it.