Skip to content
Case Study

Maximizing Detection Coverage Without Increasing SOC Alert Volume

An Equinox assessment helped an UltraViolet Cyber customer identify a faster, clearer path to closing detection gaps across its environment.

At A Glance

Industry:
Financial Services

Customer Profile:
North American Financial Institution

Security Offering:
Equinox

Region:
North America
 


 

ASSESSMENT FINDING
130% More Detection Coverage

Equinox identified a path to increase coverage from 26.6% to 61.3% of MITRE ATT&CK v19 techniques without increasing expected SOC alert volume.

Detection coverage is not static. As environments and threats change, security teams need a repeatable way to understand what their detections can see, where available telemetry limits coverage, and which improvements can maximize it.

 

The Operational Challenge

The customer already had detection coverage across every MITRE ATT&CK tactic. As its environment evolved, the team needed a faster, repeatable way to reassess its detections, identify gaps, and priortize practical improvements without adding unnecessary alert volume.

Previously, reassessing coverage relied on manual analysis that could take weeks. Equinox accelerated that work, allowing the team to identify and prioritize coverage improvements faster. The initial analysis was completed in under 30 minutes, followed by practitioner review and validation.

 

The Approach

Equinox mapped the customer’s existing detections and telemetry against a customer-specific threat model aligned to MITRE ATT&CK v19. The assessment surfaced two practical ways to maximize coverage: enable high-value vendor detections that were available but not yet active in the customer’s tools, and build targeted custom detections where needed.

Every recommendation went through UltraViolet practitioner review and remained in draft until it was validated and approved. Equinox also backtested proposed detections against 30 days of alert data and flagged any rule projected to generate more than 30 alerts for additional tuning. This kept practitioners in control and focused the work on maximizing coverage within the environment's available telemetry and alert-volume thresholds.

 

The Findings

The assessment identified a path to maximize coverage within the customer’s existing environment, increasing the number of covered MITRE ATT&CK techniques from 59 to 136 of 222 and potential coverage from 26.6% to 61.3%. That represents a 34.7-percentage-point gain (or a 130% relative increase in potential coverage) without increasing expected SOC alert volume. That broader coverage would give the team more opportunities to catch attacks early, before threats progress further.

 

Metric Assessment finding
Covered techniques 59 to 136 of 222 MITRE ATT&CK v19 techniques
Coverage rate 26.6% to 61.3%, a 130% increase in potential coverage
Initial assessment Completed in under 30 minutes, followed by practitioner review and validation
Alert volume No expected increase in SOC alert volume based on backtesting

 

The analysis made clear what the customer’s current telemetry could and could not support. Approximately 39% of the model required additional log sources. This helped the team distinguish between gaps it could address through detection changes and those that required additional telemetry.

 

A Repeatable Path Forward

The assessment created a foundation for ongoing coverage reviews. The customer can run the analysis quarterly and on demand to reassess coverage as its detections, telemetry, and threat model change. UltraViolet practitioners remain in control of reviewing, tuning, and validating every recommendation.

This gives the customer a current, evidence-backed view of where detections hold up, where telemetry limits coverage, and which improvements to prioritize next. These findings can also support more focused audit preparation and clearer conversations with security leadership.