← Back to blog
8 minKim Ytredal

MITRE ATT&CK in Practice: Mapping Your Detection Coverage

MITRE ATT&CKDetectionSOC

Most security teams know about MITRE ATT&CK, but few use it systematically. The framework isn't a checklist you fill out once — it's a living tool for understanding what you can detect, what you can't, and where to invest.

What is MITRE ATT&CK?

ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) catalogs adversary behavior into tactics and techniques. Tactics describe what the attacker is trying to achieve (Initial Access, Lateral Movement, Exfiltration), while techniques describe how they do it.

The Enterprise matrix contains over 200 techniques across 14 tactics. No organization can or should cover everything — the key is prioritization.

Map Your Detection Coverage

Step 1: Inventory Existing Detections

Review all analytics rules in Sentinel and map them to ATT&CK techniques. For each rule, note:

  • Which technique does it cover? — (e.g., T1078 — Valid Accounts)
  • Which log source is used? — (SigninLogs, SecurityEvent, etc.)
  • Quality — — does it catch real attacks or mostly generate noise?

Step 2: Visualize Coverage

Use ATT&CK Navigator (a free tool from MITRE) to color-code the matrix:

  • Green — — technique is covered with high-quality detection
  • Yellow — — technique is partially covered or has high false positive rate
  • Red — — no detection for this technique
  • Gray — — technique is not relevant to your environment

Step 3: Prioritize Based on Threat Landscape

Not all techniques are equally relevant. Prioritize based on:

  • Threat reports — — what do attackers targeting your industry use?
  • Incident history — — what have you been hit with before?
  • Infrastructure — — do you have on-prem AD? Then Kerberos attacks are relevant. Cloud only? Focus on identity techniques.

Step 4: Close Critical Gaps

For each prioritized technique without coverage:

  • Identify required log sources
  • Verify logs are being collected
  • Write detection rule (Sigma or direct KQL)
  • Test against simulated attack traffic
  • Deploy and tune

Continuous Improvement

Detection coverage isn't a project with an end date. The threat landscape changes, new infrastructure is added, and attackers develop new techniques. Review coverage quarterly and update priorities.

Measure Progress Over Time

  • Coverage rate — — percentage of prioritized techniques with active detection
  • Detection quality — — proportion of rules with low false positive rates
  • Time to coverage — — how quickly are new detections rolled out after new threat intelligence?

Common Mistakes

  • Trying to cover everything — — 100% coverage is unrealistic and unnecessary
  • Ignoring quality — — one good detection is better than ten poor ones
  • Mapping once and forgetting — — coverage needs maintenance
  • Missing log data — — you can't detect what you don't log

ForSec helps security teams map, prioritize, and improve detection coverage based on MITRE ATT&CK. We build targeted detection programs that deliver real security value.

Need help with cybersecurity?

We help Norwegian organizations protect against digital threats. Contact us for a no-obligation conversation.

Contact us