THE SAFEHOUSE / JOURNAL

Aligning OSI Layer Attacks with MITRE ATT&CK & SOC Use Cases

27 December 2025· 3 min read

Understanding attacks is useful. Detecting, investigating, and responding is what SOCs are paid for.

By mapping OSI layers → MITRE ATT&CK techniques → SOC use cases, we bridge the gap between architecture knowledge and real-world SOC operations.

Physical Layer → MITRE ATT&CK (Initial Access / Impact)

MITRE Techniques: T1190 – Exploit Public-Facing Application (via physical access), T1565 – Data Manipulation, T1499 – Endpoint Denial of Service.

SOC Use Cases: alerts from CCTV/access badge systems, power failure correlation with device outages, unexpected device reboots or link-down events, tamper alerts from servers, routers, or firewalls.

SOC Action: validate physical access logs, correlate power/network outages with access events, escalate to facilities and security immediately.

MITRE Techniques: T1557 – Adversary-in-the-Middle, T1040 – Network Sniffing, T1021 – Remote Services.

SOC Use Cases: multiple MAC addresses on a single switch port, sudden ARP table changes, VLAN hopping indicators, duplicate IP-MAC bindings.

SOC Action: trigger ARP spoofing alerts, validate switch port security violations, isolate affected VLAN, coordinate with network team.

Network Layer → MITRE ATT&CK (Discovery / Impact)

MITRE Techniques: T1018 – Remote System Discovery, T1046 – Network Service Scanning, T1498 – Network Denial of Service.

SOC Use Cases: ICMP flood or scan detection, IP spoofing indicators, abnormal routing behavior, DoS traffic patterns.

SOC Action: enable IDS/IPS correlation, block malicious IPs at the firewall, validate traffic direction and volume, inform the customer during DoS events.

Transport Layer → MITRE ATT&CK (Command & Control / Impact)

MITRE Techniques: T1071 – Application Layer Protocol, T1095 – Non-Application Layer Protocol, T1499 – Endpoint/Network DoS.

SOC Use Cases: SYN flood alerts, TCP reset anomalies, repeated half-open connections, UDP flood traffic spikes.

SOC Action: validate firewall and load balancer logs, enable SYN cookies/rate limiting, identify source ASN/IP reputation, escalate as an availability incident (P1/P2).

Session Layer → MITRE ATT&CK (Credential Access)

MITRE Techniques: T1539 – Steal Web Session Cookie, T1550 – Use Alternate Authentication Material, T1078 – Valid Accounts.

SOC Use Cases: multiple logins using the same session ID, concurrent sessions from different geolocations, token reuse or replay, abnormal logout/login cycles.

SOC Action: force session invalidation, reset affected user credentials, validate MFA enforcement, notify IAM/Identity teams.

Presentation Layer → MITRE ATT&CK (Defense Evasion / Execution)

MITRE Techniques: T1059 – Command and Scripting Interpreter, T1140 – Deobfuscate/Decode Files, T1027 – Obfuscated Files or Information.

SOC Use Cases: serialized payload anomalies, unexpected encoding/decoding operations, data format abuse in API logs, suspicious application parsing errors.

SOC Action: inspect payloads via WAF/proxy logs, validate encoding standards, escalate to AppSec for code review, block malformed requests.

Application Layer → MITRE ATT&CK (Execution / Persistence)

MITRE Techniques: T1190 – Exploit Public-Facing Application, T1059 – Command Execution, T1505 – Server-Side Component Injection, T1046 – Network Service Discovery (via app).

SOC Use Cases: SQL injection attempts, XSS payload detection, RCE exploit indicators, web shell activity, unexpected outbound connections from servers.

SOC Action: validate WAF alerts, correlate with EDR telemetry, isolate the compromised host, patch the vulnerable application, initiate the IR playbook.

How SOC Teams Should Use This Mapping

L1 Analysts: alert validation using OSI context, noise vs. real-threat identification.

L2 Analysts: MITRE technique mapping, root cause analysis, incident severity classification.

L3 / Team Leads: threat hunting hypotheses, detection engineering improvements, playbook optimization.

Why This Matters in Modern SOCs

This layered mapping improves alert explainability, enables MITRE-based reporting, strengthens customer communication, and supports audit and compliance narratives.

A mature SOC doesn't just detect alerts — it understands where, how, and why an attack occurred. The OSI model tells you where attacks happen. MITRE ATT&CK explains how attackers operate. SOC use cases define what actions to take.

When all three align, security becomes proactive, not reactive.

Related reading