Work out threat detection coverage instantly with clear inputs, formula shown and shareable results.
Counting techniques with any detection overstates coverage, because a low-confidence rule that fires constantly is not usable in practice. Weighting high-confidence detections fully and weaker ones at half gives a figure that tracks real capability. Techniques covered per log source shows where adding one telemetry type would close many gaps at once.
Weighted coverage
coverage = (high-confidence + 0.5 x partial) / techniques in scope; blind spots = in scope - any detection
No. Scope it to the techniques used by the threat groups relevant to your sector and technology, otherwise the denominator is dominated by irrelevant platforms.
Endpoint process and command-line telemetry, followed by authentication logs. Together they touch the majority of commonly observed techniques.