Advancing Cyber Threat Detection through SIEM-Based Automation and MITRE ATT&CK Aligned Analytics: A Systematic Review
Asian Journal of Research in Computer Science · pp. 233–254 · Published 23 Jan 2026
10.9734/ajrcos/2026/v19i1816Abstract
Background: The growing sophistication, scale, and persistence of cyber threats have exposed the limitations of traditional signature-based security monitoring systems. In response, modern Security Information and Event Management (SIEM) platforms increasingly integrate automation, machine learning, and structured threat intelligence frameworks most notably the MITRE ATT&CK framework to enable behavior-driven, proactive threat detection and response. Objective: This systematic review examines the effectiveness of SIEM-based automation aligned with MITRE ATT&CK analytics, with the objectives of evaluating detection performance, identifying operational and implementation challenges, and synthesizing emerging trends and policy-relevant implications for contemporary cybersecurity operations. Methods: A comprehensive literature review was conducted across IEEE Xplore, ACM Digital Library, ScienceDirect, Google Scholar, and specialized cybersecurity repositories, covering studies published between 2018 and 2024. A total of 127 peer-reviewed studies meeting predefined inclusion criteria were analyzed, focusing on SIEM automation, ATT&CK-aligned detection engineering, and empirically reported security outcomes. Results: The reviewed evidence demonstrates that SIEM platforms integrated with MITRE ATT&CK-aligned analytics achieve substantial performance gains compared with traditional approaches. Reported improvements include a 40–65% increase in threat detection accuracy, a 35–55% reduction in false positive rates, and a 50–70% decrease in mean time to detect (MTTD). Automation supported by machine learning, user and entity behavior analytics, and SOAR-enabled workflows significantly enhances the identification of advanced persistent threats, zero day exploits, and multi-stage attack campaigns. However, persistent challenges related to data quality, alert fatigue, skills shortages, model drift, and implementation complexity remain barriers to widespread adoption. Conclusions: SIEM-based automation aligned with the MITRE ATT&CK framework provides a robust and scalable foundation for modern, threat-informed cyber defense, offering measurable improvements in detection accuracy, operational efficiency, and analyst productivity. While technological advances continue to drive progress, effective adoption depends on strong data foundations, workforce development, and continuous refinement of detection engineering practices. Future research and practice are expected to focus on deeper integration with extended detection and response (XDR) platforms, AI-assisted detection engineering, and policy-driven cyber resilience strategies to address evolving threat landscapes.
Cited by 3
3 citations reported by external sources — individual citing-article records aren't available to list yet.
Related research
- A Real-Time Oil Pipeline Anti-Intrusion System Using Acoustic Sensors — shares topic coverage
- A State of the Art Survey of Machine Learning Algorithms for IoT Security — shares topic coverage
- Deep Learning Approaches for Intrusion Detection — shares topic coverage
- An Enhanced Model for Intrusion Detection in a Cloud Computing Environment — shares topic coverage
- Enhancing Network Performance: A Comprehensive Analysis of Hybrid Routing Algorithms — shares topic coverage
Article metrics
Real usage data collected on this platform.
0
Page views
0
PDF downloads
0
Outbound clicks
3
Citations
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
No views recorded yet.
Traffic sources
Referring site, by host.
No traffic recorded yet.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.