Skip to content
Calcrivo

Threat Intelligence Coverage Calculator

Score threat-intelligence coverage from ATT&CK technique visibility, indicator freshness, feed breadth and enrichment automation.

Inputs

techniques
techniques
sources
hours

KEV, EPSS and exploit chatter mapped onto your own findings

Coverage Score

59.36%

ATT&CK Technique Coverage

56.67%

Indicator Freshness

56.8%

Feed Breadth

80.0%

Techniques With No Coverage

52techniques

Grade

D — Weak

Next Step

Join KEV and EPSS to your own findings — intelligence you cannot map to an asset changes nothing

Step by step

  1. Values used

    ATT&CK techniques relevant to your threat model = 120 techniques; Techniques with intelligence coverage = 68 techniques; Distinct intelligence sources in use = 4 sources; Median age of indicators when actioned = 36 hours; Enrichment and matching are automated = Yes; Intelligence is joined to vulnerability data = No

  2. Threat Intelligence Coverage

    Score = 0.45 × technique coverage + 0.20 × indicator freshness + 0.10 × feed breadth + 0.10 × automation + 0.15 × vulnerability linkage, all on 0–100 scales so the weights sum to one.

  3. Indicator decay

    Freshness = max(0, 100 − 1.2 × median age in hours), so indicators actioned within a day retain most of their value and anything past three days scores nothing.

  4. Coverage Score

    = 59.36

  5. ATT&CK Technique Coverage

    = 56.67

  6. Indicator Freshness

    = 56.8

  7. Feed Breadth

    = 80.0

  8. Techniques With No Coverage

    = 52 techniques

  9. Grade

    = D — Weak

How it works

Technique coverage carries the most weight because breadth against a threat model beats volume of indicators, and the linkage term is worth 15 points on its own: intelligence that is never joined to your asset and vulnerability data cannot change a patching decision. Freshness decays steeply because commodity indicators — IPs, domains, hashes — are rotated within days. Threat intelligence only earns its budget when it reorders your patch queue, and this score measures the plumbing that makes that possible rather than the number of feeds you bought.

Formulas

Threat Intelligence Coverage

Score = 0.45 × technique coverage + 0.20 × indicator freshness + 0.10 × feed breadth + 0.10 × automation + 0.15 × vulnerability linkage, all on 0–100 scales so the weights sum to one.

technique coverage
Covered ÷ relevant ATT&CK techniques
freshness
100 − 1.2 × median indicator age in hours, floored at zero
feed breadth
20 points per distinct source, capped at five
linkage
Whether KEV and EPSS are mapped onto your own findings

Indicator decay

Freshness = max(0, 100 − 1.2 × median age in hours), so indicators actioned within a day retain most of their value and anything past three days scores nothing.

Frequently Asked Questions

How is Threat Intelligence Coverage calculated?

Score = 0.45 × technique coverage + 0.20 × indicator freshness + 0.10 × feed breadth + 0.10 × automation + 0.15 × vulnerability linkage, all on 0–100 scales so the weights sum to one. Technique coverage carries the most weight because breadth against a threat model beats volume of indicators, and the linkage term is worth 15 points on its own: intelligence that is never joined to your asset and vulnerability data cannot change a patching decision. Freshness decays steeply because commodity indicators — IPs, domains, hashes — are rotated within days.

Why does Threat Intelligence Coverage matter?

Threat intelligence only earns its budget when it reorders your patch queue, and this score measures the plumbing that makes that possible rather than the number of feeds you bought.

What values do I need to enter?

This calculator takes 6 inputs: ATT&CK techniques relevant to your threat model, Techniques with intelligence coverage, Distinct intelligence sources in use, Median age of indicators when actioned, Enrichment and matching are automated, Intelligence is joined to vulnerability data. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

How do I decide which ATT&CK techniques are relevant?

Start from the threat groups that target your sector and the techniques seen in your own incidents, not the whole matrix. A focused list of 100–150 techniques with real coverage is worth far more than 600 with none.

Are more feeds better?

Only to about five, and only if they see different things. Overlapping commodity feeds inflate indicator counts and analyst workload without adding visibility; one sector-specific source usually beats three general ones.

You might also need