Coverage
The Coverage tab in Intelligence is a map of the MITRE ATT&CK techniques and how well your organization covers each one: with a live detection, only with hunts, or not at all. It also marks the techniques used by the threats that are relevant to you, so you can see which gaps matter most.
Intelligence is in beta, and access is by request. It may not be enabled for your organization.
Open Coverage
Click Intelligence in the navigation menu, then the Coverage tab.
Coverage is measured per organization. If your scope is Personal, the tab shows Select an organization. Pick an organization in the Scope selector.
Read the map
Each column is an ATT&CK tactic, in attack order, such as Initial Access or Execution. The column header shows the tactic's ID and how many of its techniques have a live detection, for example "12/40 live". Each cell in a column is one technique. Sub-techniques are counted in their parent technique.
| What you see | What it means |
|---|---|
| Dark cell | Live detection: at least one detection rule for this technique is on. |
| Light cell | Hunt only: covered only by hunts in the Library or by rules running in shadow. |
| Grey cell | No coverage. |
| Dashed outline | Relevant to your threats: a threat scored as relevant to you uses this technique. |
| Warning icon | The rules for this technique are waiting for data you don't send yet, so they can't fire. Techniques covered only by hunts have no rules, so they never show it. |
Hover over a cell, or focus it with the keyboard, to see its details: the number of live and shadow rules, the number of hunts, whether the data is ready, and which relevant threats use it.
Click a cell to open the Detections tab filtered to that technique.
The map scrolls sideways on narrow screens. A tactic with many techniques shows the first ones and a +N more link.
Summary counts
Above the map:
| Count | Meaning |
|---|---|
| Techniques | All ATT&CK techniques in the map. |
| Live | Techniques with at least one live detection. When some of them have no data yet, a line under the count says how many: those rules are on but can't fire. |
| Hunt only | Techniques covered only by hunts or shadow rules. |
| No coverage | Techniques with nothing. |
| Relevant covered | Of the techniques used by threats relevant to you, how many have coverage. |
Narrow the map
| Control | What it does |
|---|---|
| Only techniques relevant to your threats | Shows only techniques that a relevant threat uses. |
| All techniques / Gaps only / Covered only | Shows every technique, only those with no coverage, or only those with some coverage. |
| ATT&CK order / Best covered first | Orders cells in ATT&CK order, or live first, then hunt only, then none. |
Your choices are kept in the page address, so a link you share opens the same view.
Where the data comes from
- Live and shadow come from your detection rules' ATT&CK tags and whether each rule is on, in shadow or off for your organization.
- Hunts come from the ATT&CK techniques on Library hunts.
- Relevant comes from the threats scored as relevant to you on the Threats tab.
- The technique list comes from the ATT&CK data in Huntbase. If it hasn't been loaded yet, the tab says No ATT&CK techniques loaded yet.
Next steps
- Intelligence overview — the headline numbers and what needs attention
- Watchers — turn detections on, off or into shadow