MITRE ATT&CK Coverage Mapping
Coverage as a number, not a claim
The coverage dashboard shows which ATT&CK techniques your active detection rules address, which are partially covered by rules in alert-only mode, which are uncovered, and which appeared in real findings at your organization in the last 90 days.
What the coverage dashboard shows
| Coverage state | What it means | Dashboard color |
|---|---|---|
| Active | At least one rule in active mode addresses this technique | Green |
| Alert-only | Rules exist but are in observe mode — signal without pages | Amber |
| Partial | Only specific sub-techniques or data sources are covered | Yellow |
| Gap | No rule addresses this technique in any mode | Red |
| Observed | This technique appeared in a real finding in the last 90 days | Blue badge |
Coverage is live, not a point-in-time export
The coverage map updates in real time as rules are deployed, promoted, or retired. When you deploy a new rule, its MITRE annotations immediately update the coverage state of the referenced techniques. No quarterly spreadsheet, no manual tagging.
Coverage gaps can be filtered by tactic (e.g., show me all uncovered Lateral Movement techniques), by data source (show me gaps I could close if I added an EDR connector), or by observed frequency (show me gaps that actually appeared in real incidents).
How coverage mapping drives detection improvement
Gap prioritization by incident frequency
Uncovered techniques that appeared in real findings at your organization are ranked first. Covering a technique you've never seen is lower priority than covering one that already fired.
Rule recommendation engine
For each gap technique, the platform suggests shipped rules that address it and the data sources required. A gap can become a shipped rule deployment in under 10 minutes if the required connector is already active.
Board-level reporting
The coverage score — overall and by tactic — is available as a dashboard widget and as a scheduled email report. One number, auditable to the underlying rule set.
Multi-tenant comparison
MSSPs can compare coverage across customer tenants, identify which tenants are below a coverage threshold, and deploy shared rules to close gaps across all tenants in a single pipeline run.
Data source gap analysis
The dashboard shows which uncovered techniques could be addressed by adding a specific data source — useful for justifying a new EDR or IdP connector purchase.
CI coverage gates
Require minimum coverage scores as a CI gate on pull requests. A PR that retires rules cannot be merged if it drops coverage below the configured threshold.
Coverage Mapping — FAQ
Which ATT&CK version is used?
The platform ships with the latest ATT&CK Enterprise matrix. Version updates are applied automatically; deprecated techniques are flagged and the rules referencing them are surfaced for review.
Can I add custom technique mappings?
Yes. Rules can be annotated with both standard ATT&CK technique IDs and custom technique IDs defined in a tenant-level taxonomy. Custom techniques appear alongside the standard matrix in the coverage view.
Does coverage account for data source quality?
Yes. A technique mapped to a rule that requires an EDR connector is only marked as covered if that EDR connector is actively sending data. A rule that cannot execute because its required source is absent is marked as partial.
Can I export coverage data to a third-party GRC tool?
Yes. Coverage state for all techniques is available via the API as a structured JSON report and can be exported as a CSV. Scheduled exports are configurable to push to S3 or a webhook endpoint.
How does ManySignal's coverage compare to a custom-built SIEM rule library?
Most custom SIEM rule libraries cover 30–50% of ATT&CK techniques, concentrated in the most common tactics. ManySignal's shipped detection library covers 80%+ of ATT&CK Enterprise techniques across cloud, identity, endpoint, and network surfaces — available from day one without a rule-engineering project.
Can we prioritise coverage gaps by likelihood and impact for our threat model?
Yes. The gap analysis view overlays your specific threat model — industry, geographies, asset types — against the coverage map. Gaps are prioritised by exploitation frequency in real-world incidents, so your detection engineering effort is directed at the highest-probability misses first.
How are coverage changes communicated when the platform ships new detections?
New and updated detections are announced in the platform changelog and visible as coverage improvements in the ATT&CK heatmap. When a new detection pack fills a gap you previously flagged, the platform notifies the analyst who filed the gap request.
Can coverage mapping be used as evidence in a SOC 2 or ISO 27001 audit?
Yes. The coverage export — showing which ATT&CK techniques are covered, which rules cover them, and which data sources those rules require — is accepted as evidence for continuous monitoring controls in SOC 2 Type II and ISO 27001 audits. Auditors can be granted read-only access to the coverage dashboard.
Does ManySignal cover ATT&CK ICS and Mobile matrices in addition to Enterprise?
ATT&CK Enterprise (cloud, Windows, macOS, Linux) is fully covered. ICS matrix coverage is available for customers with OT/ICS connectors deployed. Mobile matrix coverage is a roadmap item — contact the product team for the current status and anticipated availability.
Know your coverage before an auditor asks
The coverage dashboard is available to all ManySignal customers — no add-on required.