Map your technique detection coverage to a technique
Map your overall technique detection coverage with the technique that enables your organization to detect specific adversary techniques.
Before you begin
- Role required: sn_ti.admin, sn_si.admin: write access
- Role required: sn_ti.read: read access
About this task
You can use the technique detection coverage to get an overview into your organization's overall technique detection coverage. For example, if an adversary is attacking your organization, you see the kind of coverage that you have to detect the attacker's techniques.
The technique and ID are automatically populated for all the collections and techniques that you have activated. The coverage type and scoring definition that you have defined are available for as an option that you can select in the overall technique detection coverage.
You can map the overall technique detection coverage with the technique to complete the mapping. You can associate a technique with only one overall technique detection coverage.
The technique detection coverage mapping that you define is used in the coverage visualization in the heatmap.
Note: You can arrive at the overall technique detection coverage using your organization-specific calculations. You may use any Breach & Attack Simulation (BAS) products, the Cyber Analytics Repository (CAR), or any other methods as necessary to define the scoring definition, and use it in this procedure for the overall technique detection coverage mapping.
Procedure
Navigate to All > Threat Intelligence > MITRE ATT&CK Administration > Detection Coverage Mapping.
In this illustration, you see that the Cloud Accounts (T1078.004) sub-technique has excellent coverage in the organization and that the Overall Technique Detection Coverage is mapped to Excellent.
Detection coverage mapping.
- Review each technique and map your overall technique detection coverage based on your detection coverage definition and your organization's coverage availability.
Parent Topic:MITRE-ATT&CK administration
Related topics
Get started with MITRE-ATT&CK framework
Understand the MITRE to STIX data model
Domain separation and MITRE-ATT&CK
Set up the MITRE-ATT&CK framework
Manage CVE and technique mapping
Define the data source and detection tool mapping
Define the data source and data component mapping
Define the technique detection coverage
Define the mitigation coverage
Map your mitigation coverage to a technique
Create and map detection rules
Auto-extract technique rules for importing MITRE-ATT&CK information
Review threat group and MITRE-ATT&CK techniques mapping