Data Sources
Detection telemetry sources used by SOC and detection engineering teams.
Data Sources results
Results are validated against normalized ATT&CK source records when available; sample records are used only in development or empty-data environments.
DS0019: Service
DS0020: Snapshot
DS0002: User Account
A profile representing a user, device, service, or application used to authenticate and access resources
DS0002: User Account
A profile representing a user, device, service, or application used to authenticate and access resources
DS0042: User Interface
Visual activity on the device that could alert the user to potentially malicious behavior.
DS0034: Volume
DS0005: WMI
DS0006: Web Credential
DS0024: Windows Registry
A Windows OS hierarchical database that stores much of the information and settings for software programs, hardware devices, user preferences, and operating-system configurations[1]
DS0024: Windows Registry
A Windows OS hierarchical database that stores much of the information and settings for software programs, hardware devices, user preferences, and operating-system configurations[1]
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.