MITRE ATT&CK coverage.
Every threatDefendr detection is mapped to the MITRE ATT&CK Enterprise matrix, so coverage is measurable rather than assumed. Here is where detections sit across all fourteen tactics.
Coverage by tactic
Select a tactic to see representative techniques and their detection status. Counts reflect techniques with at least one production detection.
How coverage is maintained
Detections are managed as code. Every rule lives in version control, ships through CI with backtests against historical telemetry, and carries its ATT&CK mapping as metadata — so this matrix regenerates from the detection set itself rather than a spreadsheet. Behavioral models extend coverage to techniques that signature rules miss, and the threat-research team adds detections as new techniques are observed in the wild.
Methodology & caveats
Coverage counts a technique as covered when at least one production detection maps to it; depth varies by technique and data source. Figures are drawn from the ATT&CK Enterprise matrix and are illustrative of a typical deployment — actual coverage depends on the connectors and log sources you enable. Sub-technique depth, data-source requirements, and validation status for your environment are available in-product under Coverage → ATT&CK.