Skip to main content

MITRE ATT&CK coverage assessment, from rule export to board deck

Export your detection rules, fill in a one-workbook environment inventory, and ScopeWise maps every rule to ATT&CK, decides what is not applicable to your estate, scores coverage by tactic and hands you the gap list, the roadmap and the deck.

ScopeWise MITRE ATT&CK assessment results for the ACME sample workspace: coverage, top gaps and the per-tactic technique heatmap

The problem

Enterprise SIEMs detect about 21% of ATT&CK techniques on average, even though the telemetry they already ingest could cover more than 90% (CardinalOps, 2025 State of SIEM Detection Risk).

Mapping hundreds of rules to techniques in a spreadsheet takes days, depends on who did the tagging, and is stale by the next rule change. The deck that follows is assembled by hand every time.

What you upload, and what you never upload

You upload

  • Detection-rule export (xlsx, csv, pdf or docx) with rule name, ATT&CK tags where you have them, and the detection logic.
  • Environment workbook (assets and platforms, log sources, security tooling, crown jewels).
  • Optional scope exclusions with a reason.

You never upload

  • Credentials.
  • Raw log data.
  • Personal data.

We never ask for credentials, raw log data, or personal data. Upload rule metadata and environment inventory only. Files are stored encrypted; only minimal rule excerpts are sent for AI tagging.

Sentinel and Splunk can also be connected read-only instead of uploading a file; credentials are encrypted with AES-256-GCM and never returned by any endpoint.

How the assessment runs

1

Ingest

Rules and inventory parsed, columns auto-detected.

2

Applicability

Techniques that cannot occur on your platforms are marked not applicable, and your declared exclusions are recorded separately with their reason.

3

Tagging ladder

Existing tags first, then deterministic keyword mapping, then AI tagging only for what remains, each with a confidence score listed under Assumptions.

4

Coverage and detection strength

Coverage by tactic and technique, with a disabled rule counting as partial at best.

5

Ranked gaps and roadmap

Gaps ordered by attacker prevalence and your crown jewels, grouped into a 90-day roadmap.

Two numbers, never one

Every report shows your own rules' coverage and, separately, the coverage your security tooling claims natively. They are never merged into one figure. Coverage means a detection exists for a technique; it is not a measure of how well that detection performs.

ATT&CK v19.1

Pinned dataset, never fetched live.

858 techniques, 15 tactics

Enterprise matrix, with ICS and Mobile gated by your inventory.

63% fewer AI calls

Deterministic pre-pass on a realistic rule dump, with zero false positives on hand-verified mappings (ScopeWise internal test, Phase 6).

What you get

PDF report

Executive and detailed versions.

XLSX tracker

Every rule, mapping, gap and reference KQL for Sentinel gaps.

PPTX briefing deck

18 slides, methodology and roadmap included.

ATT&CK Navigator layer

Import into the official Navigator.

Live connectors

Microsoft Sentinel and Splunk, read-only, scheduled re-runs.

Trend between runs

What improved and what regressed since the last assessment.

Replaces the spreadsheet and the deck

The manual version of this assessment is a tagging spreadsheet, a pivot table and a slide deck rebuilt for every client. ScopeWise generates all three from the same scored data, so the numbers in the deck are the numbers in the tracker.

FAQ

Do you need my logs?

No. ScopeWise reads rule metadata and your environment inventory. It never ingests raw log data, and it never asks for credentials to do a file-based assessment.

Is it Sentinel and Splunk only?

Live connectors exist for Microsoft Sentinel and Splunk. Any other SIEM works through a file export in xlsx, csv, pdf or docx; the column mapping is auto-detected.

How is a technique decided to be not applicable?

Two ways, reported separately. Derived: the technique needs a platform your inventory says you do not run. Declared: you excluded it and gave a reason, which the report prints verbatim so the coverage figure is never misread.

Is coverage percentage the same as detection quality?

No. Coverage records that at least one detection exists for a technique. Detection strength is reported alongside it, and a disabled rule never scores better than partial.