Score threat-intelligence coverage from ATT&CK technique visibility, indicator freshness, feed breadth and enrichment automation.
Technique coverage carries the most weight because breadth against a threat model beats volume of indicators, and the linkage term is worth 15 points on its own: intelligence that is never joined to your asset and vulnerability data cannot change a patching decision. Freshness decays steeply because commodity indicators — IPs, domains, hashes — are rotated within days. Threat intelligence only earns its budget when it reorders your patch queue, and this score measures the plumbing that makes that possible rather than the number of feeds you bought.
Threat Intelligence Coverage
Score = 0.45 × technique coverage + 0.20 × indicator freshness + 0.10 × feed breadth + 0.10 × automation + 0.15 × vulnerability linkage, all on 0–100 scales so the weights sum to one.
Indicator decay
Freshness = max(0, 100 − 1.2 × median age in hours), so indicators actioned within a day retain most of their value and anything past three days scores nothing.
Score = 0.45 × technique coverage + 0.20 × indicator freshness + 0.10 × feed breadth + 0.10 × automation + 0.15 × vulnerability linkage, all on 0–100 scales so the weights sum to one. Technique coverage carries the most weight because breadth against a threat model beats volume of indicators, and the linkage term is worth 15 points on its own: intelligence that is never joined to your asset and vulnerability data cannot change a patching decision. Freshness decays steeply because commodity indicators — IPs, domains, hashes — are rotated within days.
Threat intelligence only earns its budget when it reorders your patch queue, and this score measures the plumbing that makes that possible rather than the number of feeds you bought.
This calculator takes 6 inputs: ATT&CK techniques relevant to your threat model, Techniques with intelligence coverage, Distinct intelligence sources in use, Median age of indicators when actioned, Enrichment and matching are automated, Intelligence is joined to vulnerability data. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Start from the threat groups that target your sector and the techniques seen in your own incidents, not the whole matrix. A focused list of 100–150 techniques with real coverage is worth far more than 600 with none.
Only to about five, and only if they see different things. Overlapping commodity feeds inflate indicator counts and analyst workload without adding visibility; one sector-specific source usually beats three general ones.