Skip to content
Blog

Three questions to ask about your MITRE ATT&CK coverage number

Dan Gittis

Dan Gittis

September 17, 2026

Every security leader has seen a MITRE ATT&CK coverage number by now. It shows up in a vendor pitch, a QBR slide, a board deck. The number alone says less than it appears. Two environments can each report 80 percent coverage, but only one of them may be protected at that level in practice.

Before trusting a coverage number, whether it's a vendor or your own team, three questions are worth asking.

Is the TTP coverage validated, or claimed?

A vendor rule library can report near-total technique coverage on a heatmap. That heatmap reflects what the platform catalog includes. Whether a given rule fires against your log sources, tuned for your environment, when an attacker actually executes that technique, is a separate question. A validated number comes from checking, rule by rule, whether it triggers in the environment it's meant to protect.

That distinction is where most of the gap hides. Third-party research that audits deployed detection content puts real enterprise coverage across MITRE ATT&CK techniques at around 21 percent.*

Is the coverage current, or already stale?

Security environments, telemetry, and threat frameworks change constantly. New log sources come online, tools get replaced, and MITRE comes out with new matrix versions. A coverage number checked six months ago describes an environment that may not exist anymore. The question worth asking is when a number was last checked, and whether that check happens on a schedule or only once.

Does this coverage represent one platform, or every platform?

A SIEM dashboard shows its own rules and its own data. An EDR shows its own. Neither answers the question for the stack as a whole, and lining those views up against a single MITRE ATT&CK map, technique by technique, is its own project. A number that only covers one tool can look reassuring and still miss the biggest gaps: the ones sitting in the space between platforms.

What it takes to answer all three

Most coverage numbers answer one of these three questions, if that. Few answer all three at once, mainly because doing so by hand across a full stack takes real time, and environments don't hold still long enough to make that time well spent.

Equinox is UltraViolet Cyber's way of answering all three at once. It audits what detections are live across your stack (SentinelOne, CrowdStrike, Elastic, and Panther today, with Splunk and Microsoft Defender coming), checked against real log sources, mapped to MITRE ATT&CK and MITRE ATLAS, and reviewed by a TIDE detection engineer before anything is called validated.

Once it knows what detections are live, Equinox allows us to fill the gaps where detections do not currently exist. In one recent engagement, a customer's mapped technique coverage moved from 26.6 percent to 61.3 percent with no added SOC alert volume. That's what answering all three questions looks like for a real environment.

See how it works.

 

 

 

----
*https://www.prnewswire.com/news-releases/enterprise-siems-miss-79-of-mitre-attck-techniques-used-by-adversaries-according-to-cardinalops-5th-annual-report-302473779.html