TripleSOC Key Features
A quick reference to the core capabilities available in the TripleSOC platform.
MITRE ATT&CK Mapping
Every alert in TripleSOC is automatically mapped to the MITRE ATT&CK framework — the industry-standard knowledge base of adversary tactics and techniques.
What this gives you:
- Instantly understand the adversary behavior behind any alert
- Identify coverage gaps — see which techniques your rules detect and which they don't
- Prioritize based on attack stage (Initial Access, Execution, Persistence, etc.)
The MITRE ATT&CK section in the sidebar shows a heatmap of detected techniques, letting you assess your detection coverage at a glance.
Trust Zone Intelligence
Every agent and alert carries trust zone context from TripleEnablement — Anonymous, Verified, or Secure. This gives your SOC team zero-trust context for faster, smarter triage.
See Understanding Trust Zones for the full breakdown.
File Integrity Monitoring (FIM)
TripleSOC monitors designated files and directories for unauthorized changes in real time.
What it detects:
- File creation, modification, and deletion
- Permission changes on sensitive files
- New files appearing in monitored directories
FIM is critical for detecting:
- Ransomware activity (mass file modifications)
- Rootkit installation
- Unauthorized configuration changes
- Insider data exfiltration
Navigate to the File Integrity section to view recent changes, configure monitored paths, and investigate specific events.
Security Configuration Assessment (SCA)
SCA automatically checks your endpoints against security hardening policies and compliance benchmarks.
Supported benchmarks include:
- CIS Benchmarks (Windows, Linux, macOS, Docker)
- Custom organizational policies
- Industry-specific hardening guides
Each agent receives a pass/fail/not-applicable score for every policy check. The SCA dashboard shows your overall compliance posture and highlights the highest-impact failures to fix first.
Vulnerability Detection
TripleSOC continuously inventories software packages and compares them against the National Vulnerability Database (NVD) and vendor advisories.
What it provides:
- CVE detection across endpoints, servers, and containers
- Severity scoring (CVSS) for each vulnerability
- Affected software version and remediation guidance
- Vulnerability trend over time
Navigate to the Vulnerabilities section to filter by severity, agent, or CVE ID.
Compliance Dashboards
Pre-built compliance dashboards cover major regulatory frameworks:
| Framework | Coverage |
|---|---|
| PCI DSS | Payment card security controls |
| HIPAA | Healthcare data protection |
| GDPR | EU data privacy requirements |
| NIST 800-53 | Federal security controls |
| TSC | Trust Services Criteria (SOC 2) |
Each framework dashboard shows current compliance percentage, failing controls, and trend over time — ready for audit reporting.
Active Response
TripleSOC can automatically execute response actions when specific alert conditions are met.
Built-in response actions include:
- Block an IP address at the firewall
- Isolate an endpoint from the network
- Kill a malicious process
- Run a custom remediation script
Active response rules are configured by your administrator and can be set to run automatically or require manual approval before execution.
Threat Hunting
The Threat Hunting section provides a query interface for proactive investigation — search across all collected events using structured queries, without waiting for alerts to fire.
Use threat hunting to:
- Search for indicators of compromise (IOCs)
- Investigate lateral movement across endpoints
- Reconstruct the timeline of a suspected incident