Score red team scope coverage across ATT&CK tactics, objectives achieved, detection avoided and estate actually in scope.
Coverage is dominated by scope and breadth, not by how many objectives the red team hit — a team that owns the domain in two days has proven one path and tested very little. Excluding crown jewels caps what the engagement can tell you, so the model penalises it directly, and objective success carries the smallest weight because it says more about the estate than the assessment. This is a coverage estimate for planning the next engagement, not assurance that in-scope systems are secure. A clean red team report on 30% of the estate is not a good result — it is a narrow test, and the untested 70% is where the next intrusion will start.
Red Team Coverage
coverage = 0.30×tacticCoverage + 0.30×scopeScore + 0.25×techniqueDepth + 0.15×objectiveRate, where scopeScore is the in-scope share of the estate, cut by 40% if crown jewels are excluded.
coverage = 0.30×tacticCoverage + 0.30×scopeScore + 0.25×techniqueDepth + 0.15×objectiveRate, where scopeScore is the in-scope share of the estate, cut by 40% if crown jewels are excluded. Coverage is dominated by scope and breadth, not by how many objectives the red team hit — a team that owns the domain in two days has proven one path and tested very little. Excluding crown jewels caps what the engagement can tell you, so the model penalises it directly, and objective success carries the smallest weight because it says more about the estate than the assessment. This is a coverage estimate for planning the next engagement, not assurance that in-scope systems are secure.
A clean red team report on 30% of the estate is not a good result — it is a narrow test, and the untested 70% is where the next intrusion will start.
This calculator takes 8 inputs: ATT&CK tactics exercised, Techniques executed, Objectives in scope, Objectives achieved, Actions detected by the blue team, Share of the estate in scope, Crown-jewel systems in scope, Engagement length. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No, they measure different things. Detection rate is the blue team's result and is reported separately; a red team that was caught constantly may still have covered every tactic in scope, which is the ideal outcome for both sides.
It reflects a broad multi-week engagement across several tactics. It is a yardstick for comparing engagements over time, not a target to game — fifty well-chosen techniques against crown jewels beats two hundred noisy ones in a lab segment.