Tagging Alerts to Adversaries: ML-Enabled Classification Using MITRE ATT&CK

Anum Talpur, Jörg Schröder, Liliana Kistenmacher, Georg Becker, Wolfram Wingerath, Mathias Fischer · 2025

An intrusion detection system (IDS) in an enterprise network plays an important role in identifying and alerting suspicious activity. The triggered alerts are generated along with false alarms where a legitimate activity is mistakenly classified as malicious and results in alerts fatigue. Too many alerts that are not integrated and lack related context and correlation can burden security analytics and make prioritization of threats more challenging. For security operations centers (SOCs) in an enterprise, it can result in critical alerts being overlooked or undetected, which can lead to dire attacks not being identified on time. Therefore, an automated tagging of alerts for prioritization of high-risk events is important. To overcome this challenge, we use machine learning (ML) to enrich the alerts of IDS with the real-world adversary information of the MITRE ATT&CK framework. In particular, we leverage the knowledge of the MITRE ATT&CK matrix for enterprise and apply multi-layer perceptron (MLP) and transformer-based learning in a novel way to uncover the possible correlation of alerts to known adversarial behaviors (or tactics). We evaluate our models over the recent security logs of the real enterprise network and demonstrate an accuracy of up to 95% with our automated alert classification. Extensive experiments are performed with publicly available datasets as well to demonstrate the performance of the transformer model and verify its effectiveness against different IDS setups.

Read the paper · More papers on PaperTik