MITRE ATT&CK: How to Identify and Close Security Coverage Gaps
What is MITRE ATT&CK, and how do you use it to find what your defenses miss? Map, rank, and test technique coverage instead of trusting a green heatmap.

Mars Security
Mars Security Research
The quarterly coverage review opens on a heatmap. Green nearly everywhere, two amber columns, one red cell someone promises to own. Nobody in the room can say what a green cell means. MITRE ATT&CK is a knowledge base of adversary tactics and techniques based on real-world observations. Answering what is MITRE ATT&CK properly starts in the gap between the picture and the environment it claims to describe.
Key takeaways about what is MITRE ATT&CK
- ATT&CK is a knowledge base of observed adversary behavior, organized as tactics, techniques, and sub-techniques, with a detection model that names the telemetry each behavior needs.
- Tagging rules to techniques buys you an inventory and one vocabulary shared by red, blue, and leadership. Treat the heatmap it produces as a hypothesis about your environment.
- False confidence comes from inheritance: a rule tagged to a parent technique colors every sub-technique beneath it, including ones on platforms you never instrumented.
- Rank gaps by what runs in your environment, what telemetry you hold, and how much estate one detection covers. Then test the claims on a schedule, because coverage claims expire.
What Is MITRE ATT&CK and How Does the Framework Work?
MITRE ATT&CK is a knowledge base of adversary tactics and techniques based on real-world observations, plus a taxonomy for naming that behavior. Tactics are the adversary's goal, the why. Techniques are how they reach it. Sub-techniques describe the same behavior at finer grain, and procedures are the implementations seen in incident reporting. MITRE started it in 2013 and updates the content twice a year.
Techniques live in matrices, one per domain: Enterprise, Mobile, and ICS. The Enterprise matrix alone spans Windows, macOS, Linux, IaaS, SaaS, Identity Provider, Office Suite, Network Devices, Containers, and ESXi. Fifteen tactics organize it.
| ID | Tactic | The adversary is trying to |
|---|---|---|
| TA0043 | Reconnaissance | gather information for planning |
| TA0042 | Resource Development | establish supporting resources |
| TA0001 | Initial Access | get into your network |
| TA0002 | Execution | run malicious code |
| TA0003 | Persistence | maintain a foothold |
| TA0004 | Privilege Escalation | gain higher-level permissions |
| TA0005 | Stealth | appear as normal behavior |
| TA0112 | Defense Impairment | break the tooling you watch with |
| TA0006 | Credential Access | steal account credentials |
| TA0007 | Discovery | figure out your environment |
| TA0008 | Lateral Movement | move through your environment |
| TA0009 | Collection | gather data of interest |
| TA0011 | Command and Control | control compromised systems |
| TA0010 | Exfiltration | steal data |
| TA0040 | Impact | manipulate, interrupt, or destroy |
Most coverage programs still run on a model MITRE retired. In ATT&CK v18, released in October 2025, MITRE replaced detections in techniques with Detection Strategies and Analytics and deprecated Data Sources. A technique points to a strategy, the strategy at platform-specific analytics, and each analytic names its log sources and the fields you tune.
DET0560, the strategy for Valid Accounts, shows what that buys you. Its Windows analytic asks for WinEventLog:Security EventCode=4624. Its identity provider analytic asks for saas:okta sign-in logs. Its container analytic asks for kubernetes:audit. Five analytics, five platform-specific telemetry requirements, one technique.
Two techniques carry the rest of this article: T1078 Valid Accounts, with four sub-techniques, and T1059 Command and Scripting Interpreter, with thirteen. Both sit in almost every environment, and both are heavily subdivided.
Mapping Security Controls and Detections to ATT&CK Techniques
MITRE ATT&CK mapping is inventory work. Take every detection rule you run and every preventive control you own, tag each with the technique it addresses, then load the tags into the ATT&CK Navigator as a layer and look at the shape.
That inventory earns its keep even when the picture flatters you, and the case for it is stronger than skeptics allow. A red team report and a blue team backlog stop running on two vocabularies. A CISO gets language for last year's spend that survives a board question. Intel vendors, EDR vendors, and your analysts name the same behavior the same way. None of it depends on the heatmap being accurate.
For the two techniques above:
| Technique | What you probably run | What it gets tagged as |
|---|---|---|
| T1078 Valid Accounts | Impossible-travel rule on identity provider sign-ins, plus an EventCode=4624 anomaly rule | T1078 |
| T1059 Command and Scripting Interpreter | Encoded-command PowerShell rule, plus an Office-spawns-shell parent-child rule | T1059 |
Both can land on the parent when coverage is mapped only at the technique level. If the four sub-techniques under T1078 and the thirteen under T1059 are not scored separately, the resulting layer can imply broader coverage than the underlying detections actually provide. That is where the picture starts drifting.
Finding the ATT&CK Techniques Your Defenses Don't Cover
The map is not the territory, and a coverage layer is a map you drew from your own rule inventory. Real gaps need subtracting twice: once for techniques nobody tagged, and again for techniques somebody tagged generously.
Unmapped techniques. Filter the matrix to the platforms you run, then subtract everything the inventory tagged. What remains is the honest starting list, usually shorter than people fear and rarely the list they expected.
Sub-technique inheritance. Your EventCode=4624 rule watches Domain Accounts and Local Accounts on Windows. It has nothing to say about T1078.004 Cloud Accounts in your identity provider, or about default service accounts in a cluster. The parent cell is green. Two of its four children are dark.
Platform inheritance. T1059 covers thirteen interpreters, and a rule on encoded PowerShell covers T1059.001. Unix shells on build hosts, AppleScript on macOS laptops, and the cloud API shell in T1059.009 carry separate telemetry and separate owners.
The drift has a cause worth naming. Rules get written against last quarter's artifact instead of the behavior an attacker has to repeat, which is how attacker behavior outpaced rules in the first place. A signature-shaped rule tagged to a behavior-shaped technique claims more ground than it holds.
Prioritizing Coverage Gaps Based on Threat and Business Risk
You will not close the list, so rank it. The Center for Threat-Informed Defense measured what attackers reach for. Its Sightings Ecosystem v2.0 results, published in March 2024, cover more than 1.6 million sightings from August 2021 to September 2023, and the top 15 techniques account for 82 percent of everything observed. T1059 ranks first.
Rank against your own environment:
- Does the platform exist here? ESXi techniques do not rank if you run no ESXi. Filter first, score second.
- Do you already hold the telemetry? A gap you close by writing a query outranks one that needs a new sensor and two quarters of procurement.
- What the technique gates. T1078.004 sits upstream of most cloud blast radius. Rank by what the attacker reaches next.
- How much estate one detection covers. One analytic on identity provider sign-ins covers every application behind it. One analytic on a build host covers a build host. One behavior covers many artifacts, which is the same arithmetic behind why detection outlasts remediation.
Coverage. ATT&CK catalogs behavior somebody has already observed and written up. A technique enters the matrix after a report describes it, so the matrix trails live tradecraft by however long that takes. Full coverage of ATT&CK still leaves partial coverage of your risk, and no serious program treats the matrix as the finish line.
Validating Whether Your Detections Actually Catch ATT&CK Techniques
A green cell is a claim, not a catch. Three failure modes sit between the rule you mapped and the alert an analyst reads, and none of them change the color of the cell.
The log source stopped arriving. Someone dropped a Sysmon channel for volume, an agent fell off a subnet during a migration, or the audit trail was never enabled in the new region. The rule still runs. It reads an empty stream.
The rule matches a string the attacker changes for free. An encoded-command detection keyed to one flag ordering, a single parent-child pair, a hash list. They fire on last quarter's sample and go quiet against a variant built this morning. Static signatures are the most common thing hiding behind a green cell.
The alert fires and nobody works it. Routed to a low-priority queue at 04:00, suppressed by a tuning rule written for a different problem, or arriving at a volume that trained the shift to close it on sight.
Testing is the only thing that moves a cell from claim to catch. Run the behavior in your own environment, then check whether the alert arrived at the severity you expected, in a queue somebody works. Atomic Red Team publishes small technique-mapped tests for this, and executing one takes minutes.
Say what looks the same before you claim fidelity. For T1059.001, powershell.exe running an encoded command is the daily behavior of configuration management: Intune and SCCM push encoded payloads, installers wrap them, agents run them on a schedule. For T1078.004, impossible travel is what a VPN egress node, a regional proxy, and a phone reconnecting after a flight all produce. Both need a baseline before a threshold.
Test a handful and the layer starts recording something else: what the territory returned when you walked it.
Moving From ATT&CK Mapping to Continuous Coverage Validation
Coverage maturity is a ladder, and most programs sit on the second rung believing they are on the fourth.
| Level | What you have | What you can honestly claim |
|---|---|---|
| 1. Poster | The matrix on a wall or a slide | You share a vocabulary |
| 2. Mapped | Every rule and control tagged to a technique | You know what you bought |
| 3. Gapped | Mapping filtered to your platforms, sub-techniques counted separately | You know what you skipped |
| 4. Ranked | Gaps scored on platform, telemetry, and blast radius | You know what to fund next |
| 5. Tested | Each claimed technique executed, the alert confirmed | You know what fired last time |
| 6. Continuous | Tests re-run on a schedule, drift raised as it happens | You know what fires now |
Levels 1 through 5 are a project, and a project decays from the day it closes. ATT&CK ships twice a year: v18 retired the data source model much coverage tooling was built on, and v19 split Defense Evasion into Stealth and Defense Impairment. Log sources get dropped for cost, rules get disabled during an incident and never re-enabled, and a cloud region appears in a quarter nobody scored.
Continuous coverage validation means the loop runs without a calendar invite. Rule inventory re-tagged when rules change. Telemetry checked for silence. Technique tests re-executed on a schedule, so a coverage claim expires unless something renews it. Drift raised the week it happens instead of the quarter it is discovered.
Teams on the top rung stop quoting a percentage. They report how many techniques they tested this month, how many produced the alert, and how long the failures took to fix.
Frequently Asked Questions About MITRE ATT&CK
What is MITRE ATT&CK in cyber security operations?
It is the shared reference a SOC uses to name adversary behavior across intel, detection, hunting, and red teaming. In practice, it does three jobs: it labels what an intel report describes, it tags what a rule watches for, and it exposes the gap between the two.
How is ATT&CK different from the Cyber Kill Chain?
MITRE treats them as complementary. The Cyber Kill Chain describes high-level objectives in ordered phases. ATT&CK tactics are unordered and may not all appear in one intrusion, because an adversary's tactical goals shift during an operation. ATT&CK also sits lower, describing behaviors rather than stages.
Does covering a parent technique cover its sub-techniques?
No. Sub-techniques describe distinct behaviors that usually need distinct telemetry. T1078 spans default, domain, local, and cloud accounts, and a Windows logon rule speaks to two of those at best. Score sub-techniques separately or your layer overstates coverage by a wide margin.
Where can I find the MITRE ATT&CK framework explained by MITRE itself?
MITRE publishes the knowledge base, an FAQ, and a design and philosophy paper at attack.mitre.org, alongside release notes for every version. Updates land twice a year. Read the release notes as well as the matrix, because structural changes like the v18 detection overhaul quietly break tooling built on the old model.
Which log sources does ATT&CK say I need?
Since v18, each technique points to a Detection Strategy carrying platform-specific analytics, and each analytic names its log sources, data components, and tunable fields. That is the most direct answer ATT&CK gives to a telemetry question, and far more specific than the data source entries it replaced.
Can I use ATT&CK in a report or a commercial product?
Yes, at no charge, under MITRE's terms of use. MITRE ATT&CK and ATT&CK are registered trademarks: write MITRE ATT&CK on first reference and in any headline, keep it capitalized, and never present its use as affiliation, sponsorship, or endorsement.
Pick the two techniques you would be most embarrassed to miss. Run them this week, watch what your stack does, and write the result down with a date. Do that monthly, and the heatmap becomes a measurement, which is the whole point of continuous coverage validation and the only version of ATT&CK coverage worth reporting upward.