A walk through of how the ATT&CK matrix has been applied as part of a protective monitoring service. This talk provides a background of what ATT&CK matrix is, how to use SysMon with ATT&CK matrix, the lessons identified and the opportunities to enhance the visibility of events - to aid the security analyst in responding and triaging security incidents. The audience will understand what the ATT&CK matrix is, the need to enhance event collection using endpoint agents, configuring SysMon, validation using CALDERA, deployment considerations, the importance of threat intelligence, and how to exploit within an enterprise environment.