Coverage
Coverage, coloured by proof
Most coverage maps go green when a rule exists. This one goes green when a detonation proved the rule fires - and fades back as that evidence ages past 90 days.
26
validated
0
stale
13
gaps
Three numbers, deliberately not one percentage. Averaging them into “67% covered” would hide the only distinction that matters - which bucket the work should move.
Initial Access
TA0001 · 2/4
T1566.001
Spearphishing Attachment
T1078.004
Valid Accounts: Cloud
validated 7d ago
T1190
Exploit Public-Facing App
validated 6d ago
T1133
External Remote Services
Execution
TA0002 · 3/4
T1059.001
PowerShell
validated 18d ago
T1059.003
Windows Command Shell
T1059.004
Unix Shell
validated 5d ago
T1047
WMI
validated 15d ago
Persistence
TA0003 · 4/4
Privilege Escalation
TA0004 · 1/3
T1134
Access Token Manipulation
T1068
Exploitation for Priv Esc
T1548.002
Bypass UAC
validated 17d ago
Defense Evasion
TA0005 · 3/4
Credential Access
TA0006 · 4/4
Discovery
TA0007 · 0/3
T1087.002
Domain Account Discovery
T1018
Remote System Discovery
T1482
Domain Trust Discovery
Lateral Movement
TA0008 · 3/3
Collection
TA0009 · 1/2
T1114.002
Remote Email Collection
T1530
Data from Cloud Storage
validated 82d ago
Command & Control
TA0011 · 1/3
Exfiltration
TA0010 · 1/2
T1567.002
Exfil to Cloud Storage
validated 8d ago
T1048
Exfil Over Alt Protocol
This board is a sample, not an estate
The techniques shown here are the ones our open library targets. A real programme scopes the matrix to its own threat model first - typically 120–180 techniques - and prunes the rest rather than carrying permanent red cells that nobody intends to close.
Telemetry gaps come before rule gaps
Before writing rules for an empty column, check whether the data exists. Most sparse Command & Control coverage is a DNS and network telemetry problem, and ten new rules against logs you do not collect will turn cells green while changing nothing.
Why coverage maps deceive →