ATT&CK coverage

The same results in MITRE's vocabulary rather than ours. Every test the client runs is mapped to one or more ATT&CK technique IDs, so a defender can line this up against their own coverage map instead of learning our test names.

No published reports yet

Technique coverage appears once 3 runs have been published. Each technique also needs 3 reports of its own before it is listed, so the tactic columns fill in gradually.

How the mapping works

Each of the client's tests declares the ATT&CK techniques it exercises — the registry refuses to load a test that declares none, so nothing can quietly drop out of this view. A technique is covered when at least one test exercising it was detected or blocked: if any of several tests for one technique is caught, the defences cover the technique.

The client can also export an ATT&CK Navigator layer for a single run (--formats navigator), which overlays the same result on your own coverage map.