We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Cybersecurity
  2. ATT&CK coverage assessment
MITRE ATT&CK coverage assessment for US businesses

Four hundred detection rules, and nobody in the building can say which adversary behaviors they fail to catch.

The framework is a knowledge base of how adversaries actually behave and a shared vocabulary for those actions across the whole lifecycle of an attack. Mapping your detections onto it converts a count of rules into a coverage picture with the gaps clearly visible, which is precisely the picture your board, your insurer and every incident retrospective genuinely need.

Book a coverage assessmentSee how it works
MITRE ATT&CK coverage assessment for US organizations
  • 15 tacticsIn the Enterprise matrix
  • Tactic, technique, sub-techniqueWhy, how, and specifically how
  • Bi-annualThe stated ATT&CK update cadence
  • Gaps, not countsWhat the assessment actually produces
The question this answers

If somebody were inside your network this morning, at what stage would you first notice?

Almost no security program can answer that, because its reporting was built around volume rather than around what an adversary actually does.

  • Counting alerts, counting rules and counting tools all measure activity rather than coverage. An estate running four hundred rules concentrated into two tactics is considerably weaker than one running eighty spread deliberately across the whole lifecycle.
  • Framing this across the lifecycle matters because detecting something late is still detecting it. Seeing the damage while missing the entry, the persistence and the movement sideways means you find out at the moment of harm rather than at any of the earlier points where intervening would have been cheap.
  • An assessment turns all of that into a map. Every tactic receives an honest position, running from confident detection through partial coverage or telemetry alone, down to nothing at all. Only the honest positions are useful, and self-assessment written to flatter defeats the entire purpose of doing it.
  • It also hands a board something they can genuinely decide on. Approving detection work becomes a question of which stage of an intrusion you are prepared to be blind at, rather than a budget request carrying a technical justification nobody around the table can evaluate.
Ask us to map your coverage
What a coverage assessment does

Eight things it establishes that a rule count cannot.

Any security team can tell you how many detections it runs. Very few can tell you which adversary behaviors would pass through entirely unnoticed, and that is the question a board, an insurer or an actual incident puts to you.

A shared taxonomy for adversary behavior

It is a knowledge base describing how adversaries behave, alongside a taxonomy for their actions across the full lifecycle of an attack. That shared vocabulary is exactly what lets a detection team, an offensive team and a board all discuss the same thing without anybody translating between three different dialects.

Why, how, and specifically how

A tactic captures why somebody does something. A technique captures how they achieve that goal. A sub-technique describes the specific behavior used to do it. Coverage that sounds comprehensive at the level of tactics is nearly always considerably thinner once you descend to sub-techniques.

Fifteen tactics across the Enterprise matrix

Beginning with reconnaissance and building the resources for an attack, moving through gaining initial access, executing code, establishing persistence and escalating privilege, then on to stealing credentials, looking around, moving sideways, collecting what they came for, maintaining command and control, taking the data out, and finally causing the damage.

Stealth and Defense Impairment are now separate

One covers somebody concealing their actions so that everything looks like ordinary activity. The other covers deliberately breaking your security mechanisms, your logging pipelines and your tooling, so that defenders can neither see nor trust what is in front of them. Those are genuinely different problems and they need genuinely different detections.

The gaps are the deliverable

Where this earns its keep is in showing you what you cannot see. A tactic carrying no meaningful detection is a blind spot with a name and a date attached, and something named can be planned around rather than discovered by everybody simultaneously during an incident.

It spans more than the endpoint

The domains reach across enterprise IT, meaning Windows, macOS, Linux, network hardware and containers, across cloud systems covering infrastructure, subscription software, office suites and identity providers, across mobile on both Android and Apple, and across industrial control systems.

It gives detection work a priority order

Rather than adding rules because a vendor happened to ship them last quarter, mapping coverage lets you add detections precisely where a gap exists in a tactic that matters given who is likely to come after you. That turns detection engineering from something reactive into something planned.

It exposes duplication as well as absence

Most estates discover several techniques covered five times over by tools that overlap heavily, while the technique next to them has nothing whatsoever. Retiring that duplication is frequently what pays for the work needed to close the genuine gaps.

The Enterprise tactics

Fifteen stages, and what somebody attacking you is trying to accomplish at each one.

Drawn from the published enterprise tactic descriptions. An assessment gives every one of these an honest status rather than an aspirational one.

Tactic

Reconnaissance

ID
TA0043
What the adversary is trying to do
Gather information to plan future operations

Tactic

Resource Development

ID
TA0042
What the adversary is trying to do
Establish resources to support operations

Tactic

Initial Access

ID
TA0001
What the adversary is trying to do
Get into your network

Tactic

Execution

ID
TA0002
What the adversary is trying to do
Run malicious code

Tactic

Persistence

ID
TA0003
What the adversary is trying to do
Maintain their foothold

Tactic

Privilege Escalation

ID
TA0004
What the adversary is trying to do
Gain higher-level permissions

Tactic

Stealth

ID
TA0005
What the adversary is trying to do
Hide and conceal actions, appearing as normal behavior

Tactic

Defense Impairment

ID
TA0112
What the adversary is trying to do
Break security mechanisms, pipelines, and tooling

Tactic

Credential Access

ID
TA0006
What the adversary is trying to do
Steal account names and passwords

Tactic

Discovery

ID
TA0007
What the adversary is trying to do
Figure out your environment

Tactic

Lateral Movement

ID
TA0008
What the adversary is trying to do
Move through your environment

Tactic

Collection

ID
TA0009
What the adversary is trying to do
Gather data of interest to their goal

Tactic

Command and Control

ID
TA0011
What the adversary is trying to do
Communicate with compromised systems to control them

Tactic

Exfiltration

ID
TA0010
What the adversary is trying to do
Steal data

Tactic

Impact

ID
TA0040
What the adversary is trying to do
Manipulate, interrupt, or destroy systems and data
TacticIDWhat the adversary is trying to do
ReconnaissanceTA0043Gather information to plan future operations
Resource DevelopmentTA0042Establish resources to support operations
Initial AccessTA0001Get into your network
ExecutionTA0002Run malicious code
PersistenceTA0003Maintain their foothold
Privilege EscalationTA0004Gain higher-level permissions
StealthTA0005Hide and conceal actions, appearing as normal behavior
Defense ImpairmentTA0112Break security mechanisms, pipelines, and tooling
Credential AccessTA0006Steal account names and passwords
DiscoveryTA0007Figure out your environment
Lateral MovementTA0008Move through your environment
CollectionTA0009Gather data of interest to their goal
Command and ControlTA0011Communicate with compromised systems to control them
ExfiltrationTA0010Steal data
ImpactTA0040Manipulate, interrupt, or destroy systems and data
How we approach it

Four things that make a coverage map honest.

An inflated coverage map is genuinely worse than having none at all, because it manufactures a confidence that will not survive contact with a real intrusion.

We map at sub-technique level where it matters

A sub-technique describes the specific behavior used to achieve a goal. Coverage claimed at the level of tactics almost invariably looks better than what sits underneath it, and mapping at the level a detection genuinely operates at removes that inflation entirely.

We validate a sample rather than trusting the map

A mapped detection that has never fired here is an assumption wearing the clothes of a control. Safely validating a representative set separates the detections that work from the detections that merely exist, and that difference is consistently larger than any team expects it to be.

We treat telemetry as the binding constraint

Nothing can be detected that was never collected. Where a tactic has no coverage at all, the cause is frequently an absent data source rather than an absent rule, and that distinction changes both what the fix costs and the order in which it has to happen.

We prioritize against your threat profile, not the matrix

Covering every technique is neither achievable nor worth achieving. Prioritizing against what genuinely threatens your sector, your data and your particular architecture produces a much shorter list that improves your position considerably faster.

How an engagement runs

Four phases across roughly six to ten weeks.

Doing the mapping is quick work. Validating that the mapped detections genuinely fire, and then closing the gaps that actually matter, is where the calendar goes.
  1. 01
    Weeks 1 to 2

    Inventory telemetry and detections

    Which data sources you genuinely collect, from which platforms, kept for how long, and which detections currently run against any of it. Coverage can never exceed telemetry, so the data source picture puts a hard ceiling on everything that follows.

    • Telemetry sources documented with retention
    • Detection inventory extracted from each platform
    • Platform coverage identified across endpoint, cloud, identity, and network
    • Known blind spots recorded upfront
  2. 02
    Weeks 3 to 5

    Map to tactics and techniques

    Every detection mapped to the techniques it genuinely addresses rather than the ones printed on a vendor datasheet. Mapped down at sub-technique level wherever the detection is specific enough, because coverage claimed at the level of tactics overstates the real position by a considerable margin.

    • Detections mapped to techniques and sub-techniques
    • Coverage status assigned per tactic honestly
    • Duplicated coverage identified
    • Vendor claims separated from validated coverage
  3. 03
    Weeks 6 to 8

    Validate rather than assume

    A mapped detection that has never once fired in your environment is a hypothesis rather than a control. Safely validating a representative sample of them turns the whole map from a documentation exercise into an actual statement about what would be seen.

    • Representative techniques validated safely
    • Detections that failed to fire identified
    • Tuning issues separated from coverage issues
    • Map corrected against validation results
  4. 04
    Weeks 9 to 10

    Prioritize and plan

    Gaps ordered by who actually threatens your company rather than by how much of the matrix is still white. Nobody needs complete coverage of every technique, and chasing it is an excellent way to spend a year without improving your position in any meaningful respect.

    • Gap list prioritized against your threat profile
    • Detection engineering backlog created
    • Telemetry additions specified where needed
    • Board-level coverage summary produced
Where this comes up

Six situations that prompt an assessment.

What prompts this is nearly always a question nobody could answer, either across a board table or in the room after an incident.

A board asking what the security spend bought

Counting tools and counting alerts answers none of it. A coverage map framed around what somebody attacking you is trying to accomplish at each stage gives a board a way to evaluate where they stand and to decide, deliberately, where they are prepared to be blind.

An organization after an incident nobody detected

The question in every retrospective is which stage ought to have caught it. Mapping the intrusion path onto the tactics, then mapping your existing detections onto that same frame, shows immediately whether what failed was coverage, telemetry or tuning.

A regulated firm evidencing detection capability

When an examiner, an auditor or an underwriter asks how you measure detection capability, an honest coverage map against a recognized taxonomy is a far stronger answer than a list of products alongside a description of who is on call this weekend.

A business consolidating overlapping tools

Mapping coverage routinely finds the same technique detected five separate times by five different products, while the technique immediately beside it has nothing at all. That picture is precisely what makes a consolidation decision defensible rather than purely a matter of cost.

An operation with industrial control systems

Industrial control systems have their own domain alongside enterprise and mobile. Manufacturers and operators treating operational technology as outside the scope of detection generally discover that assumption during an assessment, which is a considerably better place to discover it than during an incident.

A team planning its detection engineering year

With no coverage baseline, detection work follows whatever a vendor happened to ship in the last release. With one, it follows an ordered backlog tied to specific named gaps, which is both far easier to justify at the start of a year and far easier to measure at the end of one.

Three positions

How US organizations understand their detection coverage.

The middle column feels rigorous and is nothing of the sort, because a vendor mapping describes what their product could theoretically detect rather than what your particular deployment of it actually does.
Reflects your actual configuration
Validated coverage mapYes
Vendor-supplied mappingNo
Rule and alert countsNot applicable
Distinguishes tactic from sub-technique
Validated coverage mapYes
Vendor-supplied mappingUsually not
Rule and alert countsNo
Validated by testing
Validated coverage mapSampled
Vendor-supplied mappingNo
Rule and alert countsNo
Shows blind spots
Validated coverage mapExplicitly
Vendor-supplied mappingOptimistically
Rule and alert countsNot at all
Identifies duplicated spend
Validated coverage mapYes
Vendor-supplied mappingNo
Rule and alert countsNo
Prioritized to your threat profile
Validated coverage mapYes
Vendor-supplied mappingGeneric
Rule and alert countsNo
Usable in a board conversation
Validated coverage mapYes
Vendor-supplied mappingMisleading
Rule and alert countsMeaningless
Drives an engineering backlog
Validated coverage mapYes
Vendor-supplied mappingRarely
Rule and alert countsNo
Effort to produce
Validated coverage mapWeeks
Vendor-supplied mappingMinutes
Rule and alert countsNone
Confidence during an incident
Validated coverage mapJustified
Vendor-supplied mappingMisplaced
Rule and alert countsAbsent
Feature
Validated coverage map
Vendor-supplied mapping
Rule and alert counts
Reflects your actual configuration
YesNoNot applicable
Distinguishes tactic from sub-technique
YesUsually notNo
Validated by testing
SampledNoNo
Shows blind spots
ExplicitlyOptimisticallyNot at all
Identifies duplicated spend
YesNoNo
Prioritized to your threat profile
YesGenericNo
Usable in a board conversation
YesMisleadingMeaningless
Drives an engineering backlog
YesRarelyNo
Effort to produce
WeeksMinutesNone
Confidence during an incident
JustifiedMisplacedAbsent
Reading the output

Four possible statuses, and only one of them means you would genuinely see the behavior.

A coverage map is worthless unless the statuses are honest, which means the scale has to separate capability from configuration and both from validation.

  • Validated. A detection exists, it is mapped to the technique, and somebody has watched it fire in your environment and produce an alert a human would actually act on. This is the only status supporting a confident answer during an incident review.
  • Configured, and never validated. A detection exists and is mapped, and no one has ever confirmed it fires in this environment. Extremely common, and wrong surprisingly often, because tuning decisions, missing telemetry and incomplete deployment all quietly break detections that look entirely correct on screen.
  • Telemetry and nothing more. The data that would reveal the behavior is being collected and kept, and absolutely nothing is examining it. That status is genuinely good news, because a detection can be written against it quickly rather than requiring somebody to stand up a new data source first.
  • Nothing at all. No detection and no telemetry either. That is a blind spot rather than a gap, and closing it begins with collecting data rather than with writing detections, which makes it slower and considerably more expensive than anything above it on this list.
How an engagement runs

Five steps, and the third is where the comfortable assumptions stop.

Mapping is pleasant, tidy work. Validating that the mapped detections genuinely fire is where your real position becomes visible to everybody.
  1. 1

    Establish what telemetry exists

    Every data source across endpoints, identity, the cloud control planes, the network, and industrial systems where those exist, each with its retention period recorded. Coverage is bounded absolutely by collection, so this step sets the ceiling for everything after it.

  2. 2

    Inventory and map detections

    Every rule from every platform, mapped onto the techniques and sub-techniques it genuinely addresses. Whatever mapping a vendor supplies gets treated as an input rather than accepted at face value, because it describes what their product can do rather than what your deployment of it does.

  3. 3

    Validate a representative sample

    Selected techniques tested safely to establish three things: whether the mapped detection fires at all, whether it produces an alert somebody could act on, and whether any human would ever see it. Detections that exist and do not fire are far and away the most common finding.

  4. 4

    Produce the honest map

    All fifteen tactics given a status backed by evidence, every gap stated plainly rather than softened, and the duplication identified. The entire value here is accuracy, which means an uncomfortable map is a successful one.

  5. 5

    Prioritize and hand over a backlog

    The gaps ranked against who actually threatens you, separated into telemetry work and detection work, with a summary a board can read sitting alongside the engineering detail. A reassessment gets scheduled, since the taxonomy itself is revised twice a year.

Straight answers

What organizations ask about ATT&CK coverage.

A knowledge base describing how adversaries behave, alongside a taxonomy covering their actions across the whole lifecycle of an attack. It gives detection teams, offensive teams, vendors and boards one shared vocabulary for describing what attackers genuinely do.

A tactic captures why, meaning what somebody is trying to accomplish at that point. A technique captures how they go about achieving it. A sub-technique sits one level below that again, describing the specific behavior involved.

Fifteen in total. They begin with reconnaissance and building resources, then getting in, executing code, staying there, escalating privilege, staying hidden, breaking your defenses, stealing credentials, exploring, moving sideways, gathering what they came for, maintaining control, taking the data out, and finally doing the damage.

One is somebody concealing what they are doing so that all of it resembles ordinary activity. The other is somebody deliberately breaking your security mechanisms, your logging pipelines and your tooling so that defenders can neither see nor trust anything. Different behaviors entirely, and they require different detections.

It is a useful input and it is not an answer. A vendor map describes what the product can detect in principle, not what your deployment detects with your configuration, your telemetry, and your tuning. Those diverge more than most teams expect.

No. Full coverage of every technique is neither achievable nor a sensible objective. The goal is deliberate coverage across the lifecycle, weighted to your threat profile, with the remaining gaps documented and accepted rather than unknown.

No. The domains cover Enterprise IT including Windows, macOS, Linux, network devices, and containers, cloud including infrastructure, software as a service, office suites, and identity providers, plus Mobile and industrial control systems. Estates that map only endpoint telemetry consistently show strong coverage that does not extend to where the identity attacks happen.

By testing a representative sample of techniques in a controlled way, agreed in advance with your team, and observing whether the mapped detection fires and whether it produces an alert somebody would act on. Scope and safety are agreed before anything runs.

No. A penetration test seeks a path to an objective. A coverage assessment measures whether you would see adversary behavior across the lifecycle. They complement each other, and a test conducted without a coverage baseline teaches you less than it could.

Not necessarily. Organizations using a managed detection and response provider often benefit most, because the assessment establishes what the provider actually covers rather than what the contract implies, which is a question worth answering before renewal.

Underwriters and examiners increasingly ask how you would detect an intrusion, not just what tools you own. A validated coverage map against a recognized taxonomy answers that question with evidence: which stages of an intrusion you would see, which you would not, and what the plan is for the gaps. It is a materially stronger answer than a product list.

At least annually, and after any significant change to your estate or tooling. The taxonomy itself is updated on a stated bi-annual cadence, so a map more than a year old describes both an older environment and an older frame of reference. Engagements are scoped by the number of detection platforms and whether validation testing is included, with a custom quote. The free first step: ask your team which of the fifteen tactics they would confidently detect today, and see how quickly the confident list gets short.
Before the assessment

Twelve questions worth answering first.

The telemetry block is the binding constraint on everything else. Detection coverage can never exceed the data you genuinely collect and keep.

Telemetry

  • Which platforms send us data?
    Endpoint, cloud, identity, network.
  • How long do we retain it?
    Retention bounds detection.
  • Are cloud control planes covered?
    Often missed entirely.
  • Is identity telemetry included?
    Credential Access lives there.

Detections

  • Can we export the rule inventory?
    From every platform.
  • Do we know which rules have ever fired?
    A revealing question.
  • Are vendor mappings taken at face value?
    They should not be.
  • Who owns detection engineering?
    Often nobody explicitly.

Purpose

  • What is our actual threat profile?
    It sets the priorities.
  • Who will read the output?
    Board or engineering, or both.
  • Is there capacity to act on gaps?
    Otherwise it is a report.
  • When will we reassess?
    ATT&CK updates bi-annually.
Related reading

The pages around this one.

Sentinel analytics rules

Where detection rules are built and tuned.

Learn more

KQL threat hunting

Looking for what the detections did not catch.

Learn more

SOC as a service

The team watching what the coverage map describes.

Learn more
Next step

Ask your team which of the fifteen tactics they would confidently detect today.

The confident list usually gets short quickly, and the tactics that drop off it are your coverage assessment before anybody has run one.

Book a coverage assessmentSee cybersecurity services

Related Services

Explore more solutions that work great with this service

Microsoft Sentinel

Cloud-native SIEM and threat intelligence

Learn more

Penetration Testing

Penetration testing for US businesses across external, internal, web

Learn more

Vulnerability Assessment

Vulnerability assessment for US businesses across external attack

Learn more

Incident Response Plan Development

Incident response plan development for US organizations: decision

Learn more

Cyber Incident Response

Cyber incident response for US businesses. 24/7 on-call IR engineers

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA