MITRE ATT&CK Coverage Calculator
Measure ATT&CK Enterprise coverage across tactics, techniques and sub-techniques, weighted by detection confidence.
Inputs
ATT&CK Enterprise v15 has ~201 techniques; exclude platforms you do not run.
~450 sub-techniques exist across the full matrix.
Robust to minor tool changes; not a single brittle command-line string.
In-Scope Technique Coverage
60.0%
In-Scope Sub-Technique Coverage
49.3%
Tactic Coverage
78.6%
Out of the 14 ATT&CK Enterprise tactics.
Coverage of the Full Enterprise Matrix
47.8%
Confidence-Weighted Coverage
45.8%
Techniques With No Detection
64techniques
Coverage Maturity
Established — good breadth, depth uneven
Step by step
Values used
Techniques with a working detection = 96 techniques; Techniques in scope for your environment = 160 techniques; Sub-techniques with a working detection = 148 sub-techniques; Sub-techniques in scope = 300 sub-techniques; Tactics with at least one high-confidence detection = 11 tactics; Techniques with high-confidence detection = 58 techniques
MITRE ATT&CK Coverage
Technique coverage = techniques detected ÷ techniques in scope. Sub-technique coverage and tactic coverage (out of 14) are computed the same way.
Confidence weighting
Confidence-weighted coverage = (high-confidence techniques + 0.4 × remaining detected techniques) ÷ in-scope techniques.
In-Scope Technique Coverage
= 60.0
In-Scope Sub-Technique Coverage
= 49.3
Tactic Coverage
= 78.6
Coverage of the Full Enterprise Matrix
= 47.8
Confidence-Weighted Coverage
= 45.8
Techniques With No Detection
= 64 techniques
How it works
Coverage is measured against in-scope techniques, not the whole matrix, because a detection for a macOS technique in a Windows-only estate is not a gap you should be scored on. The confidence weighting then discounts brittle detections to 40% credit, which is what stops a library of fragile string matches from reading as full coverage. ATT&CK coverage is the language boards, auditors and red teams all share, and an honest 45% with known gaps is far more useful than a 90% heatmap built from detections that break the first time an attacker renames a binary.
Formulas
MITRE ATT&CK Coverage
Technique coverage = techniques detected ÷ techniques in scope. Sub-technique coverage and tactic coverage (out of 14) are computed the same way.
- 14
- Tactics in ATT&CK Enterprise, Reconnaissance through Impact
- 201
- Approximate technique count in the full Enterprise matrix
- in scope
- Techniques applicable to the platforms and services you actually run
Confidence weighting
Confidence-weighted coverage = (high-confidence techniques + 0.4 × remaining detected techniques) ÷ in-scope techniques.
- high-confidence
- Detections resilient to tool and command-line variation
- 0.4
- Partial credit for brittle or low-fidelity detections
Frequently Asked Questions
How is MITRE ATT&CK Coverage calculated?
Technique coverage = techniques detected ÷ techniques in scope. Sub-technique coverage and tactic coverage (out of 14) are computed the same way. Coverage is measured against in-scope techniques, not the whole matrix, because a detection for a macOS technique in a Windows-only estate is not a gap you should be scored on. The confidence weighting then discounts brittle detections to 40% credit, which is what stops a library of fragile string matches from reading as full coverage.
Why does MITRE ATT&CK Coverage matter?
ATT&CK coverage is the language boards, auditors and red teams all share, and an honest 45% with known gaps is far more useful than a 90% heatmap built from detections that break the first time an attacker renames a binary.
What values do I need to enter?
This calculator takes 6 inputs: Techniques with a working detection, Techniques in scope for your environment, Sub-techniques with a working detection, Sub-techniques in scope, Tactics with at least one high-confidence detection, Techniques with high-confidence detection. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is 100% ATT&CK coverage a sensible goal?
No. Some techniques have no reliable telemetry, some are indistinguishable from normal administration, and chasing the long tail costs more than it returns. Prioritise techniques that appear in threat intel for your sector and that sit on the critical path of real intrusions.
Should I count sub-techniques or techniques?
Report techniques to leadership and track sub-techniques in engineering. A technique marked 'covered' because one of its eight sub-techniques is detected is the most common way ATT&CK heatmaps mislead.