Skip to content

Coverage

Coverage, coloured by proof

Most coverage maps go green when a rule exists. This one goes green when a detonation proved the rule fires - and fades back as that evidence ages past 90 days.

26

validated

0

stale

13

gaps

Three numbers, deliberately not one percentage. Averaging them into “67% covered” would hide the only distinction that matters - which bucket the work should move.

Validated - Detonation proved it fires within 90 days
Stale - Rule exists, proof is older than 90 days
Gap - No published rule

Initial Access

TA0001 · 2/4

Privilege Escalation

TA0004 · 1/3

T1134

Access Token Manipulation

T1068

Exploitation for Priv Esc

T1548.002

Bypass UAC

validated 17d ago

Discovery

TA0007 · 0/3

T1087.002

Domain Account Discovery

T1018

Remote System Discovery

T1482

Domain Trust Discovery

Collection

TA0009 · 1/2

T1114.002

Remote Email Collection

T1530

Data from Cloud Storage

validated 82d ago

Command & Control

TA0011 · 1/3

T1071.001

Web Protocols

T1071.004

DNS

validated 19d ago

T1572

Protocol Tunneling

Exfiltration

TA0010 · 1/2

This board is a sample, not an estate

The techniques shown here are the ones our open library targets. A real programme scopes the matrix to its own threat model first - typically 120–180 techniques - and prunes the rest rather than carrying permanent red cells that nobody intends to close.

Telemetry gaps come before rule gaps

Before writing rules for an empty column, check whether the data exists. Most sparse Command & Control coverage is a DNS and network telemetry problem, and ten new rules against logs you do not collect will turn cells green while changing nothing.

Why coverage maps deceive →