← CYBERNETICSINTERN.COMCYBERNETIC INTERN
Detection EngineeringFOUNDATION

What ATT&CK mapping is actually for

Mapping rules to techniques is a vocabulary for describing coverage, not a scoreboard. Counting covered techniques rewards the wrong work.

Mapping detections to ATT&CK techniques is worth doing. Treating the resulting count as a score is where it goes wrong.

The value is a shared vocabulary. When threat intel describes an actor using T1078, you can ask what you have for T1078 and get an answer instead of a conversation. It lets detection, intel and response talk about the same thing without redefining it each time.

The trap is that a technique is marked covered when one rule points at it. That ignores everything that decides whether coverage is real. Does the telemetry actually arrive from the hosts that matter? Does the rule catch the common procedures, or one narrow variant? Has it fired once in a year, and if not, is that because the behaviour is rare or because the rule is broken?

A heat map made of those answers is genuinely useful. A heat map made of tag counts rewards adding shallow rules for uncovered techniques rather than deepening the ones that matter, and it turns green long before you are safe.

If you keep a coverage map, record two things beside each technique: which log source it depends on, and when the rule last matched anything. Those two columns turn a scoreboard back into an engineering document.

CHECK YOURSELF

A team reports coverage of 180 of 200 techniques. What does that number reliably tell you?

SHOW THE ANSWER

That at least one rule references each of those techniques

Why. The count measures whether a rule is tagged with a technique, not whether it works, whether the telemetry reaches it, or whether it covers the technique's procedures. One weak rule marks a technique covered exactly as convincingly as five good ones.

REFERENCE

← ALL DETECTION ENGINEERING