Four hundred detection rules, and nobody in the building can say which adversary behaviors they fail to catch.
The framework is a knowledge base of how adversaries actually behave and a shared vocabulary for those actions across the whole lifecycle of an attack. Mapping your detections onto it converts a count of rules into a coverage picture with the gaps clearly visible, which is precisely the picture your board, your insurer and every incident retrospective genuinely need.

- 15 tacticsIn the Enterprise matrix
- Tactic, technique, sub-techniqueWhy, how, and specifically how
- Bi-annualThe stated ATT&CK update cadence
- Gaps, not countsWhat the assessment actually produces
If somebody were inside your network this morning, at what stage would you first notice?
Almost no security program can answer that, because its reporting was built around volume rather than around what an adversary actually does.
- Counting alerts, counting rules and counting tools all measure activity rather than coverage. An estate running four hundred rules concentrated into two tactics is considerably weaker than one running eighty spread deliberately across the whole lifecycle.
- Framing this across the lifecycle matters because detecting something late is still detecting it. Seeing the damage while missing the entry, the persistence and the movement sideways means you find out at the moment of harm rather than at any of the earlier points where intervening would have been cheap.
- An assessment turns all of that into a map. Every tactic receives an honest position, running from confident detection through partial coverage or telemetry alone, down to nothing at all. Only the honest positions are useful, and self-assessment written to flatter defeats the entire purpose of doing it.
- It also hands a board something they can genuinely decide on. Approving detection work becomes a question of which stage of an intrusion you are prepared to be blind at, rather than a budget request carrying a technical justification nobody around the table can evaluate.
Eight things it establishes that a rule count cannot.
A shared taxonomy for adversary behavior
It is a knowledge base describing how adversaries behave, alongside a taxonomy for their actions across the full lifecycle of an attack. That shared vocabulary is exactly what lets a detection team, an offensive team and a board all discuss the same thing without anybody translating between three different dialects.
Why, how, and specifically how
A tactic captures why somebody does something. A technique captures how they achieve that goal. A sub-technique describes the specific behavior used to do it. Coverage that sounds comprehensive at the level of tactics is nearly always considerably thinner once you descend to sub-techniques.
Fifteen tactics across the Enterprise matrix
Beginning with reconnaissance and building the resources for an attack, moving through gaining initial access, executing code, establishing persistence and escalating privilege, then on to stealing credentials, looking around, moving sideways, collecting what they came for, maintaining command and control, taking the data out, and finally causing the damage.
Stealth and Defense Impairment are now separate
One covers somebody concealing their actions so that everything looks like ordinary activity. The other covers deliberately breaking your security mechanisms, your logging pipelines and your tooling, so that defenders can neither see nor trust what is in front of them. Those are genuinely different problems and they need genuinely different detections.
The gaps are the deliverable
Where this earns its keep is in showing you what you cannot see. A tactic carrying no meaningful detection is a blind spot with a name and a date attached, and something named can be planned around rather than discovered by everybody simultaneously during an incident.
It spans more than the endpoint
The domains reach across enterprise IT, meaning Windows, macOS, Linux, network hardware and containers, across cloud systems covering infrastructure, subscription software, office suites and identity providers, across mobile on both Android and Apple, and across industrial control systems.
It gives detection work a priority order
Rather than adding rules because a vendor happened to ship them last quarter, mapping coverage lets you add detections precisely where a gap exists in a tactic that matters given who is likely to come after you. That turns detection engineering from something reactive into something planned.
It exposes duplication as well as absence
Most estates discover several techniques covered five times over by tools that overlap heavily, while the technique next to them has nothing whatsoever. Retiring that duplication is frequently what pays for the work needed to close the genuine gaps.
Fifteen stages, and what somebody attacking you is trying to accomplish at each one.
Tactic
Reconnaissance
- ID
- TA0043
- What the adversary is trying to do
- Gather information to plan future operations
Tactic
Resource Development
- ID
- TA0042
- What the adversary is trying to do
- Establish resources to support operations
Tactic
Initial Access
- ID
- TA0001
- What the adversary is trying to do
- Get into your network
Tactic
Execution
- ID
- TA0002
- What the adversary is trying to do
- Run malicious code
Tactic
Persistence
- ID
- TA0003
- What the adversary is trying to do
- Maintain their foothold
Tactic
Privilege Escalation
- ID
- TA0004
- What the adversary is trying to do
- Gain higher-level permissions
Tactic
Stealth
- ID
- TA0005
- What the adversary is trying to do
- Hide and conceal actions, appearing as normal behavior
Tactic
Defense Impairment
- ID
- TA0112
- What the adversary is trying to do
- Break security mechanisms, pipelines, and tooling
Tactic
Credential Access
- ID
- TA0006
- What the adversary is trying to do
- Steal account names and passwords
Tactic
Discovery
- ID
- TA0007
- What the adversary is trying to do
- Figure out your environment
Tactic
Lateral Movement
- ID
- TA0008
- What the adversary is trying to do
- Move through your environment
Tactic
Collection
- ID
- TA0009
- What the adversary is trying to do
- Gather data of interest to their goal
Tactic
Command and Control
- ID
- TA0011
- What the adversary is trying to do
- Communicate with compromised systems to control them
Tactic
Exfiltration
- ID
- TA0010
- What the adversary is trying to do
- Steal data
Tactic
Impact
- ID
- TA0040
- What the adversary is trying to do
- Manipulate, interrupt, or destroy systems and data
Four things that make a coverage map honest.
We map at sub-technique level where it matters
A sub-technique describes the specific behavior used to achieve a goal. Coverage claimed at the level of tactics almost invariably looks better than what sits underneath it, and mapping at the level a detection genuinely operates at removes that inflation entirely.
We validate a sample rather than trusting the map
A mapped detection that has never fired here is an assumption wearing the clothes of a control. Safely validating a representative set separates the detections that work from the detections that merely exist, and that difference is consistently larger than any team expects it to be.
We treat telemetry as the binding constraint
Nothing can be detected that was never collected. Where a tactic has no coverage at all, the cause is frequently an absent data source rather than an absent rule, and that distinction changes both what the fix costs and the order in which it has to happen.
We prioritize against your threat profile, not the matrix
Covering every technique is neither achievable nor worth achieving. Prioritizing against what genuinely threatens your sector, your data and your particular architecture produces a much shorter list that improves your position considerably faster.
Four phases across roughly six to ten weeks.
- 01Weeks 1 to 2
Inventory telemetry and detections
Which data sources you genuinely collect, from which platforms, kept for how long, and which detections currently run against any of it. Coverage can never exceed telemetry, so the data source picture puts a hard ceiling on everything that follows.
- Telemetry sources documented with retention
- Detection inventory extracted from each platform
- Platform coverage identified across endpoint, cloud, identity, and network
- Known blind spots recorded upfront
- 02Weeks 3 to 5
Map to tactics and techniques
Every detection mapped to the techniques it genuinely addresses rather than the ones printed on a vendor datasheet. Mapped down at sub-technique level wherever the detection is specific enough, because coverage claimed at the level of tactics overstates the real position by a considerable margin.
- Detections mapped to techniques and sub-techniques
- Coverage status assigned per tactic honestly
- Duplicated coverage identified
- Vendor claims separated from validated coverage
- 03Weeks 6 to 8
Validate rather than assume
A mapped detection that has never once fired in your environment is a hypothesis rather than a control. Safely validating a representative sample of them turns the whole map from a documentation exercise into an actual statement about what would be seen.
- Representative techniques validated safely
- Detections that failed to fire identified
- Tuning issues separated from coverage issues
- Map corrected against validation results
- 04Weeks 9 to 10
Prioritize and plan
Gaps ordered by who actually threatens your company rather than by how much of the matrix is still white. Nobody needs complete coverage of every technique, and chasing it is an excellent way to spend a year without improving your position in any meaningful respect.
- Gap list prioritized against your threat profile
- Detection engineering backlog created
- Telemetry additions specified where needed
- Board-level coverage summary produced
Six situations that prompt an assessment.
A board asking what the security spend bought
Counting tools and counting alerts answers none of it. A coverage map framed around what somebody attacking you is trying to accomplish at each stage gives a board a way to evaluate where they stand and to decide, deliberately, where they are prepared to be blind.
An organization after an incident nobody detected
The question in every retrospective is which stage ought to have caught it. Mapping the intrusion path onto the tactics, then mapping your existing detections onto that same frame, shows immediately whether what failed was coverage, telemetry or tuning.
A regulated firm evidencing detection capability
When an examiner, an auditor or an underwriter asks how you measure detection capability, an honest coverage map against a recognized taxonomy is a far stronger answer than a list of products alongside a description of who is on call this weekend.
A business consolidating overlapping tools
Mapping coverage routinely finds the same technique detected five separate times by five different products, while the technique immediately beside it has nothing at all. That picture is precisely what makes a consolidation decision defensible rather than purely a matter of cost.
An operation with industrial control systems
Industrial control systems have their own domain alongside enterprise and mobile. Manufacturers and operators treating operational technology as outside the scope of detection generally discover that assumption during an assessment, which is a considerably better place to discover it than during an incident.
A team planning its detection engineering year
With no coverage baseline, detection work follows whatever a vendor happened to ship in the last release. With one, it follows an ordered backlog tied to specific named gaps, which is both far easier to justify at the start of a year and far easier to measure at the end of one.
How US organizations understand their detection coverage.
| Feature | Validated coverage map | Vendor-supplied mapping | Rule and alert counts |
|---|---|---|---|
Reflects your actual configuration | Yes | No | Not applicable |
Distinguishes tactic from sub-technique | Yes | Usually not | No |
Validated by testing | Sampled | No | No |
Shows blind spots | Explicitly | Optimistically | Not at all |
Identifies duplicated spend | Yes | No | No |
Prioritized to your threat profile | Yes | Generic | No |
Usable in a board conversation | Yes | Misleading | Meaningless |
Drives an engineering backlog | Yes | Rarely | No |
Effort to produce | Weeks | Minutes | None |
Confidence during an incident | Justified | Misplaced | Absent |
Four possible statuses, and only one of them means you would genuinely see the behavior.
A coverage map is worthless unless the statuses are honest, which means the scale has to separate capability from configuration and both from validation.
- Validated. A detection exists, it is mapped to the technique, and somebody has watched it fire in your environment and produce an alert a human would actually act on. This is the only status supporting a confident answer during an incident review.
- Configured, and never validated. A detection exists and is mapped, and no one has ever confirmed it fires in this environment. Extremely common, and wrong surprisingly often, because tuning decisions, missing telemetry and incomplete deployment all quietly break detections that look entirely correct on screen.
- Telemetry and nothing more. The data that would reveal the behavior is being collected and kept, and absolutely nothing is examining it. That status is genuinely good news, because a detection can be written against it quickly rather than requiring somebody to stand up a new data source first.
- Nothing at all. No detection and no telemetry either. That is a blind spot rather than a gap, and closing it begins with collecting data rather than with writing detections, which makes it slower and considerably more expensive than anything above it on this list.
Five steps, and the third is where the comfortable assumptions stop.
- 1
Establish what telemetry exists
Every data source across endpoints, identity, the cloud control planes, the network, and industrial systems where those exist, each with its retention period recorded. Coverage is bounded absolutely by collection, so this step sets the ceiling for everything after it.
- 2
Inventory and map detections
Every rule from every platform, mapped onto the techniques and sub-techniques it genuinely addresses. Whatever mapping a vendor supplies gets treated as an input rather than accepted at face value, because it describes what their product can do rather than what your deployment of it does.
- 3
Validate a representative sample
Selected techniques tested safely to establish three things: whether the mapped detection fires at all, whether it produces an alert somebody could act on, and whether any human would ever see it. Detections that exist and do not fire are far and away the most common finding.
- 4
Produce the honest map
All fifteen tactics given a status backed by evidence, every gap stated plainly rather than softened, and the duplication identified. The entire value here is accuracy, which means an uncomfortable map is a successful one.
- 5
Prioritize and hand over a backlog
The gaps ranked against who actually threatens you, separated into telemetry work and detection work, with a summary a board can read sitting alongside the engineering detail. A reassessment gets scheduled, since the taxonomy itself is revised twice a year.
What organizations ask about ATT&CK coverage.
Twelve questions worth answering first.
Telemetry
- Which platforms send us data?Endpoint, cloud, identity, network.
- How long do we retain it?Retention bounds detection.
- Are cloud control planes covered?Often missed entirely.
- Is identity telemetry included?Credential Access lives there.
Detections
- Can we export the rule inventory?From every platform.
- Do we know which rules have ever fired?A revealing question.
- Are vendor mappings taken at face value?They should not be.
- Who owns detection engineering?Often nobody explicitly.
Purpose
- What is our actual threat profile?It sets the priorities.
- Who will read the output?Board or engineering, or both.
- Is there capacity to act on gaps?Otherwise it is a report.
- When will we reassess?ATT&CK updates bi-annually.
Ask your team which of the fifteen tactics they would confidently detect today.
The confident list usually gets short quickly, and the tactics that drop off it are your coverage assessment before anybody has run one.
Related Services
Explore more solutions that work great with this service
Microsoft Sentinel
Cloud-native SIEM and threat intelligence
Learn morePenetration Testing
Penetration testing for US businesses across external, internal, web
Learn moreVulnerability Assessment
Vulnerability assessment for US businesses across external attack
Learn moreIncident Response Plan Development
Incident response plan development for US organizations: decision
Learn moreCyber Incident Response
Cyber incident response for US businesses. 24/7 on-call IR engineers
Learn more