UPDATED · 20 JUN 2026·EDIT ON GITHUB
REFERENCE · ATT&CK COVERAGE

MITRE ATT&CK coverage.

Every threatDefendr detection is mapped to the MITRE ATT&CK Enterprise matrix, so coverage is measurable rather than assumed. Here is where detections sit across all fourteen tactics.

201
Techniques with active detections
87%
Of the Enterprise matrix
14 / 14
Tactics covered
1,900+
Managed detection rules
Full ≥ 90%Strong 70–89%Partial < 70%

Coverage by tactic

Select a tactic to see representative techniques and their detection status. Counts reflect techniques with at least one production detection.

{{ activeCode }}
{{ activeName }}
{{ activeCount }} covered
{{ tech.id }}{{ tech.name }}{{ tech.status }}

How coverage is maintained

Detections are managed as code. Every rule lives in version control, ships through CI with backtests against historical telemetry, and carries its ATT&CK mapping as metadata — so this matrix regenerates from the detection set itself rather than a spreadsheet. Behavioral models extend coverage to techniques that signature rules miss, and the threat-research team adds detections as new techniques are observed in the wild.

SEE ALSOShip and version your own mapped detections with the Detection-as-Code guide, or explore live adversary coverage on the Threat Intelligence page.

Methodology & caveats

Coverage counts a technique as covered when at least one production detection maps to it; depth varies by technique and data source. Figures are drawn from the ATT&CK Enterprise matrix and are illustrative of a typical deployment — actual coverage depends on the connectors and log sources you enable. Sub-technique depth, data-source requirements, and validation status for your environment are available in-product under Coverage → ATT&CK.

← PREVDetection Pipeline NEXT →Detection-as-Code