Coverage Advisor

SO

Coverage Gap Advisor

Identify MITRE ATT&CK coverage gaps and get actionable detection recommendations

Techniques Covered

5

Coverage %

50%

Critical Gaps

5

Recommended Detections

10

Gap Analysis

TechniqueNameTacticCoveragePriorityRecommendationAction
T1059Command and Scripting InterpreterExecutionCoveredlowExisting PowerShell & Bash rules active
T1059.001PowerShellExecutionCoveredlowScriptBlock logging rule deployed
T1071Application Layer ProtocolCommand & ControlPartialmediumAdd DNS-over-HTTPS detection rule
T1053Scheduled Task/JobPersistenceGaphighDeploy schtasks / cron anomaly detection
T1078Valid AccountsInitial AccessPartialhighCorrelate impossible-travel with auth logs
T1021Remote ServicesLateral MovementGaphighMonitor RDP/SSH lateral pivots
T1486Data Encrypted for ImpactImpactCoveredlowRansomware canary files active
T1027Obfuscated Files or InformationDefense EvasionGaphighAdd entropy-based payload analysis
T1562Impair DefensesDefense EvasionPartialmediumDetect tamper of EDR services
T1110Brute ForceCredential AccessCoveredlowRate-limit rules deployed across tenants
T1048Exfiltration Over Alternative ProtocolExfiltrationGaphighMonitor DNS/ICMP tunneling patterns
T1087Account DiscoveryDiscoveryPartialmediumAlert on bulk LDAP enumeration
T1547Boot or Logon Autostart ExecutionPersistenceGapmediumRegistry run-key change monitoring
T1569System ServicesExecutionCoveredlowService creation audit rule active
T1190Exploit Public-Facing ApplicationInitial AccessPartialhighWAF log correlation with CVE feeds