MITRE ATT&CK coverage assessment, from rule export to board deck
Export your detection rules, fill in a one-workbook environment inventory, and ScopeWise maps every rule to ATT&CK, decides what is not applicable to your estate, scores coverage by tactic and hands you the gap list, the roadmap and the deck.

The problem
Enterprise SIEMs detect about 21% of ATT&CK techniques on average, even though the telemetry they already ingest could cover more than 90% (CardinalOps, 2025 State of SIEM Detection Risk).
Mapping hundreds of rules to techniques in a spreadsheet takes days, depends on who did the tagging, and is stale by the next rule change. The deck that follows is assembled by hand every time.
What you upload, and what you never upload
You upload
- Detection-rule export (xlsx, csv, pdf or docx) with rule name, ATT&CK tags where you have them, and the detection logic.
- Environment workbook (assets and platforms, log sources, security tooling, crown jewels).
- Optional scope exclusions with a reason.
You never upload
- Credentials.
- Raw log data.
- Personal data.
We never ask for credentials, raw log data, or personal data. Upload rule metadata and environment inventory only. Files are stored encrypted; only minimal rule excerpts are sent for AI tagging.
Sentinel and Splunk can also be connected read-only instead of uploading a file; credentials are encrypted with AES-256-GCM and never returned by any endpoint.
How the assessment runs
Ingest
Rules and inventory parsed, columns auto-detected.
Applicability
Techniques that cannot occur on your platforms are marked not applicable, and your declared exclusions are recorded separately with their reason.
Tagging ladder
Existing tags first, then deterministic keyword mapping, then AI tagging only for what remains, each with a confidence score listed under Assumptions.
Coverage and detection strength
Coverage by tactic and technique, with a disabled rule counting as partial at best.
Ranked gaps and roadmap
Gaps ordered by attacker prevalence and your crown jewels, grouped into a 90-day roadmap.
Two numbers, never one
Every report shows your own rules' coverage and, separately, the coverage your security tooling claims natively. They are never merged into one figure. Coverage means a detection exists for a technique; it is not a measure of how well that detection performs.
ATT&CK v19.1
Pinned dataset, never fetched live.
858 techniques, 15 tactics
Enterprise matrix, with ICS and Mobile gated by your inventory.
63% fewer AI calls
Deterministic pre-pass on a realistic rule dump, with zero false positives on hand-verified mappings (ScopeWise internal test, Phase 6).
What you get
PDF report
Executive and detailed versions.
XLSX tracker
Every rule, mapping, gap and reference KQL for Sentinel gaps.
PPTX briefing deck
18 slides, methodology and roadmap included.
ATT&CK Navigator layer
Import into the official Navigator.
Live connectors
Microsoft Sentinel and Splunk, read-only, scheduled re-runs.
Trend between runs
What improved and what regressed since the last assessment.
Replaces the spreadsheet and the deck
The manual version of this assessment is a tagging spreadsheet, a pivot table and a slide deck rebuilt for every client. ScopeWise generates all three from the same scored data, so the numbers in the deck are the numbers in the tracker.
FAQ
Do you need my logs?
No. ScopeWise reads rule metadata and your environment inventory. It never ingests raw log data, and it never asks for credentials to do a file-based assessment.
Is it Sentinel and Splunk only?
Live connectors exist for Microsoft Sentinel and Splunk. Any other SIEM works through a file export in xlsx, csv, pdf or docx; the column mapping is auto-detected.
How is a technique decided to be not applicable?
Two ways, reported separately. Derived: the technique needs a platform your inventory says you do not run. Declared: you excluded it and gave a reason, which the report prints verbatim so the coverage figure is never misread.
Is coverage percentage the same as detection quality?
No. Coverage records that at least one detection exists for a technique. Detection strength is reported alongside it, and a disabled rule never scores better than partial.