Security alerts often appear as isolated events, making it difficult to understand whether they are part of an attack. In this article we explore how Trisul maps network detections to MITRE ATT&CK tactics and techniques, adding behavioral context to alerts and visualizing activity directly within the ATT&CK matrix.