Understanding attacks is useful. Detecting, investigating, and responding is what SOCs are paid for.
By mapping OSI layers → MITRE ATT&CK techniques → SOC use cases, we bridge the gap between architecture knowledge and real-world SOC operations.
Physical Layer → MITRE ATT&CK (Initial Access / Impact)
MITRE Techniques: T1190 – Exploit Public-Facing Application (via physical access), T1565 – Data Manipulation, T1499 – Endpoint Denial of Service.
SOC Use Cases: alerts from CCTV/access badge systems, power failure correlation with device outages, unexpected device reboots or link-down events, tamper alerts from servers, routers, or firewalls.
SOC Action: validate physical access logs, correlate power/network outages with access events, escalate to facilities and security immediately.
Data Link Layer → MITRE ATT&CK (Lateral Movement)
MITRE Techniques: T1557 – Adversary-in-the-Middle, T1040 – Network Sniffing, T1021 – Remote Services.
SOC Use Cases: multiple MAC addresses on a single switch port, sudden ARP table changes, VLAN hopping indicators, duplicate IP-MAC bindings.
SOC Action: trigger ARP spoofing alerts, validate switch port security violations, isolate affected VLAN, coordinate with network team.
Network Layer → MITRE ATT&CK (Discovery / Impact)
MITRE Techniques: T1018 – Remote System Discovery, T1046 – Network Service Scanning, T1498 – Network Denial of Service.
SOC Use Cases: ICMP flood or scan detection, IP spoofing indicators, abnormal routing behavior, DoS traffic patterns.
SOC Action: enable IDS/IPS correlation, block malicious IPs at the firewall, validate traffic direction and volume, inform the customer during DoS events.
Transport Layer → MITRE ATT&CK (Command & Control / Impact)
MITRE Techniques: T1071 – Application Layer Protocol, T1095 – Non-Application Layer Protocol, T1499 – Endpoint/Network DoS.
SOC Use Cases: SYN flood alerts, TCP reset anomalies, repeated half-open connections, UDP flood traffic spikes.
SOC Action: validate firewall and load balancer logs, enable SYN cookies/rate limiting, identify source ASN/IP reputation, escalate as an availability incident (P1/P2).
Session Layer → MITRE ATT&CK (Credential Access)
MITRE Techniques: T1539 – Steal Web Session Cookie, T1550 – Use Alternate Authentication Material, T1078 – Valid Accounts.
SOC Use Cases: multiple logins using the same session ID, concurrent sessions from different geolocations, token reuse or replay, abnormal logout/login cycles.
SOC Action: force session invalidation, reset affected user credentials, validate MFA enforcement, notify IAM/Identity teams.
Presentation Layer → MITRE ATT&CK (Defense Evasion / Execution)
MITRE Techniques: T1059 – Command and Scripting Interpreter, T1140 – Deobfuscate/Decode Files, T1027 – Obfuscated Files or Information.
SOC Use Cases: serialized payload anomalies, unexpected encoding/decoding operations, data format abuse in API logs, suspicious application parsing errors.
SOC Action: inspect payloads via WAF/proxy logs, validate encoding standards, escalate to AppSec for code review, block malformed requests.
Application Layer → MITRE ATT&CK (Execution / Persistence)
MITRE Techniques: T1190 – Exploit Public-Facing Application, T1059 – Command Execution, T1505 – Server-Side Component Injection, T1046 – Network Service Discovery (via app).
SOC Use Cases: SQL injection attempts, XSS payload detection, RCE exploit indicators, web shell activity, unexpected outbound connections from servers.
SOC Action: validate WAF alerts, correlate with EDR telemetry, isolate the compromised host, patch the vulnerable application, initiate the IR playbook.
How SOC Teams Should Use This Mapping
L1 Analysts: alert validation using OSI context, noise vs. real-threat identification.
L2 Analysts: MITRE technique mapping, root cause analysis, incident severity classification.
L3 / Team Leads: threat hunting hypotheses, detection engineering improvements, playbook optimization.
Why This Matters in Modern SOCs
This layered mapping improves alert explainability, enables MITRE-based reporting, strengthens customer communication, and supports audit and compliance narratives.
A mature SOC doesn't just detect alerts — it understands where, how, and why an attack occurred. The OSI model tells you where attacks happen. MITRE ATT&CK explains how attackers operate. SOC use cases define what actions to take.
When all three align, security becomes proactive, not reactive.