Measure ATT&CK Enterprise coverage across tactics, techniques and sub-techniques, weighted by detection confidence.
Coverage is measured against in-scope techniques, not the whole matrix, because a detection for a macOS technique in a Windows-only estate is not a gap you should be scored on. The confidence weighting then discounts brittle detections to 40% credit, which is what stops a library of fragile string matches from reading as full coverage. ATT&CK coverage is the language boards, auditors and red teams all share, and an honest 45% with known gaps is far more useful than a 90% heatmap built from detections that break the first time an attacker renames a binary.
MITRE ATT&CK Coverage
Technique coverage = techniques detected ÷ techniques in scope. Sub-technique coverage and tactic coverage (out of 14) are computed the same way.
Confidence weighting
Confidence-weighted coverage = (high-confidence techniques + 0.4 × remaining detected techniques) ÷ in-scope techniques.
Technique coverage = techniques detected ÷ techniques in scope. Sub-technique coverage and tactic coverage (out of 14) are computed the same way. Coverage is measured against in-scope techniques, not the whole matrix, because a detection for a macOS technique in a Windows-only estate is not a gap you should be scored on. The confidence weighting then discounts brittle detections to 40% credit, which is what stops a library of fragile string matches from reading as full coverage.
ATT&CK coverage is the language boards, auditors and red teams all share, and an honest 45% with known gaps is far more useful than a 90% heatmap built from detections that break the first time an attacker renames a binary.
This calculator takes 6 inputs: Techniques with a working detection, Techniques in scope for your environment, Sub-techniques with a working detection, Sub-techniques in scope, Tactics with at least one high-confidence detection, Techniques with high-confidence detection. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No. Some techniques have no reliable telemetry, some are indistinguishable from normal administration, and chasing the long tail costs more than it returns. Prioritise techniques that appear in threat intel for your sector and that sit on the critical path of real intrusions.
Report techniques to leadership and track sub-techniques in engineering. A technique marked 'covered' because one of its eight sub-techniques is detected is the most common way ATT&CK heatmaps mislead.