The rules cover attacks on Windows, macOS and Linux. While the content of individual rules is Soteria's IP, you can check the dynamic MITRE ATT&CK mapping here:

Did this answer your question?