Threat Intelligence Coverage Calculator
Score threat-intelligence coverage from ATT&CK technique visibility, indicator freshness, feed breadth and enrichment automation.
Inputs
KEV, EPSS and exploit chatter mapped onto your own findings
Coverage Score
59.36%
ATT&CK Technique Coverage
56.67%
Indicator Freshness
56.8%
Feed Breadth
80.0%
Techniques With No Coverage
52techniques
Grade
D — Weak
Next Step
Join KEV and EPSS to your own findings — intelligence you cannot map to an asset changes nothing
Step by step
Values used
ATT&CK techniques relevant to your threat model = 120 techniques; Techniques with intelligence coverage = 68 techniques; Distinct intelligence sources in use = 4 sources; Median age of indicators when actioned = 36 hours; Enrichment and matching are automated = Yes; Intelligence is joined to vulnerability data = No
Threat Intelligence Coverage
Score = 0.45 × technique coverage + 0.20 × indicator freshness + 0.10 × feed breadth + 0.10 × automation + 0.15 × vulnerability linkage, all on 0–100 scales so the weights sum to one.
Indicator decay
Freshness = max(0, 100 − 1.2 × median age in hours), so indicators actioned within a day retain most of their value and anything past three days scores nothing.
Coverage Score
= 59.36
ATT&CK Technique Coverage
= 56.67
Indicator Freshness
= 56.8
Feed Breadth
= 80.0
Techniques With No Coverage
= 52 techniques
Grade
= D — Weak
How it works
Technique coverage carries the most weight because breadth against a threat model beats volume of indicators, and the linkage term is worth 15 points on its own: intelligence that is never joined to your asset and vulnerability data cannot change a patching decision. Freshness decays steeply because commodity indicators — IPs, domains, hashes — are rotated within days. Threat intelligence only earns its budget when it reorders your patch queue, and this score measures the plumbing that makes that possible rather than the number of feeds you bought.
Formulas
Threat Intelligence Coverage
Score = 0.45 × technique coverage + 0.20 × indicator freshness + 0.10 × feed breadth + 0.10 × automation + 0.15 × vulnerability linkage, all on 0–100 scales so the weights sum to one.
- technique coverage
- Covered ÷ relevant ATT&CK techniques
- freshness
- 100 − 1.2 × median indicator age in hours, floored at zero
- feed breadth
- 20 points per distinct source, capped at five
- linkage
- Whether KEV and EPSS are mapped onto your own findings
Indicator decay
Freshness = max(0, 100 − 1.2 × median age in hours), so indicators actioned within a day retain most of their value and anything past three days scores nothing.
Frequently Asked Questions
How is Threat Intelligence Coverage calculated?
Score = 0.45 × technique coverage + 0.20 × indicator freshness + 0.10 × feed breadth + 0.10 × automation + 0.15 × vulnerability linkage, all on 0–100 scales so the weights sum to one. Technique coverage carries the most weight because breadth against a threat model beats volume of indicators, and the linkage term is worth 15 points on its own: intelligence that is never joined to your asset and vulnerability data cannot change a patching decision. Freshness decays steeply because commodity indicators — IPs, domains, hashes — are rotated within days.
Why does Threat Intelligence Coverage matter?
Threat intelligence only earns its budget when it reorders your patch queue, and this score measures the plumbing that makes that possible rather than the number of feeds you bought.
What values do I need to enter?
This calculator takes 6 inputs: ATT&CK techniques relevant to your threat model, Techniques with intelligence coverage, Distinct intelligence sources in use, Median age of indicators when actioned, Enrichment and matching are automated, Intelligence is joined to vulnerability data. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
How do I decide which ATT&CK techniques are relevant?
Start from the threat groups that target your sector and the techniques seen in your own incidents, not the whole matrix. A focused list of 100–150 techniques with real coverage is worth far more than 600 with none.
Are more feeds better?
Only to about five, and only if they see different things. Overlapping commodity feeds inflate indicator counts and analyst workload without adding visibility; one sector-specific source usually beats three general ones.
You might also need
- Patch Priority CalculatorCommonly used together
- Exploit Probability CalculatorCommonly used together
- Vulnerability Management Maturity CalculatorCommonly used together
- CVSS v3 Score CalculatorAlso in Vulnerability Management
- Vulnerability Health Score CalculatorAlso in Vulnerability Management
- Asset Exposure CalculatorAlso in Vulnerability Management