MITRE ATT&CK Coverage
Tamandua maps current and intended detections to the MITRE ATT&CK framework. Coverage is evidence-backed only where rules, telemetry, and validation runs exist.
Coverage Summary
| Metric | Value |
|---|
| Total Techniques Mapped | Partial; publish counts only from dated validation artifacts |
| Tactics Mapped | Partial; validation-dependent |
| Enterprise Matrix Coverage | Partial; no percentage without a dated benchmark artifact |
| Sub-techniques Mapped | Partial; validation-dependent |
Coverage by Tactic
TA0001 - Initial Access
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| Phishing | T1566 | Mapped | Sigma, ML |
| Phishing: Spearphishing Attachment | T1566.001 | Mapped | YARA, Sigma |
| Phishing: Spearphishing Link | T1566.002 | Mapped | Sigma, IOC |
| Exploit Public-Facing Application | T1190 | Partial | Behavioral |
| External Remote Services | T1133 | Mapped | Sigma |
| Valid Accounts | T1078 | Mapped | Sigma |
| Drive-by Compromise | T1189 | Partial | ML, YARA |
| Supply Chain Compromise | T1195 | Mapped | Sigma |
TA0002 - Execution
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| Command and Scripting Interpreter | T1059 | Mapped | Sigma, YARA |
| PowerShell | T1059.001 | Mapped | Sigma |
| Windows Command Shell | T1059.003 | Mapped | Sigma |
| Visual Basic | T1059.005 | Mapped | Sigma |
| Python | T1059.006 | Mapped | Sigma |
| JavaScript | T1059.007 | Mapped | Sigma |
| Scheduled Task/Job | T1053 | Mapped | Sigma |
| Scheduled Task | T1053.005 | Mapped | Sigma |
| User Execution | T1204 | Mapped | Sigma, Behavioral |
| Malicious Link | T1204.001 | Mapped | Sigma |
| Malicious File | T1204.002 | Mapped | YARA, ML |
| Native API | T1106 | Mapped | Behavioral |
| Windows Management Instrumentation | T1047 | Mapped | Sigma |
| Inter-Process Communication | T1559 | Partial | Behavioral |
| Shared Modules | T1129 | Mapped | Sigma |
TA0003 - Persistence
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| Boot or Logon Autostart Execution | T1547 | Mapped | Sigma |
| Registry Run Keys | T1547.001 | Mapped | Sigma |
| Authentication Package | T1547.002 | Mapped | Sigma |
| Time Providers | T1547.003 | Mapped | Sigma |
| Winlogon Helper DLL | T1547.004 | Mapped | Sigma |
| Scheduled Task/Job | T1053 | Mapped | Sigma |
| Create Account | T1136 | Mapped | Sigma |
| Local Account | T1136.001 | Mapped | Sigma |
| Domain Account | T1136.002 | Mapped | Sigma |
| Create or Modify System Process | T1543 | Mapped | Sigma |
| Windows Service | T1543.003 | Mapped | Sigma |
| Event Triggered Execution | T1546 | Mapped | Sigma |
| Change Default File Association | T1546.001 | Mapped | Sigma |
| WMI Event Subscription | T1546.003 | Mapped | Sigma |
| Startup Items | T1037.005 | Mapped | Sigma |
| BITS Jobs | T1197 | Mapped | Sigma |
TA0004 - Privilege Escalation
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| Abuse Elevation Control Mechanism | T1548 | Mapped | Sigma |
| Bypass UAC | T1548.002 | Mapped | Sigma |
| Access Token Manipulation | T1134 | Mapped | Behavioral |
| Token Impersonation | T1134.001 | Mapped | Behavioral |
| Create Process with Token | T1134.002 | Mapped | Behavioral |
| Process Injection | T1055 | Mapped | Behavioral, YARA |
| DLL Injection | T1055.001 | Mapped | Behavioral |
| PE Injection | T1055.002 | Mapped | YARA |
| Process Hollowing | T1055.012 | Mapped | Behavioral |
| Exploitation for Privilege Escalation | T1068 | Partial | ML |
| Valid Accounts | T1078 | Mapped | Sigma |
TA0005 - Defense Evasion
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| Indicator Removal | T1070 | Mapped | Sigma |
| Clear Windows Event Logs | T1070.001 | Mapped | Sigma |
| Clear Linux Logs | T1070.002 | Mapped | Sigma |
| File Deletion | T1070.004 | Mapped | Sigma |
| Timestomp | T1070.006 | Mapped | Sigma |
| Impair Defenses | T1562 | Mapped | Sigma |
| Disable Windows Defender | T1562.001 | Mapped | Sigma |
| Disable Firewall | T1562.004 | Mapped | Sigma |
| Masquerading | T1036 | Mapped | Sigma, ML |
| Match Legitimate Name | T1036.005 | Mapped | Sigma |
| Obfuscated Files | T1027 | Mapped | YARA, ML |
| Binary Padding | T1027.001 | Mapped | YARA |
| Steganography | T1027.003 | Partial | ML |
| Process Injection | T1055 | Mapped | Behavioral |
| Signed Binary Proxy Execution | T1218 | Mapped | Sigma |
| CMSTP | T1218.003 | Mapped | Sigma |
| MSBuild | T1218.004 | Mapped | Sigma |
| Mshta | T1218.005 | Mapped | Sigma |
| Regsvr32 | T1218.010 | Mapped | Sigma |
| Rundll32 | T1218.011 | Mapped | Sigma |
| Indirect Command Execution | T1202 | Mapped | Sigma |
| ETW Tampering | - | Mapped | Sigma |
| Command Line Spoofing | - | Mapped | Sigma |
| PPID Spoofing | - | Mapped | Behavioral |
TA0006 - Credential Access
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| OS Credential Dumping | T1003 | Mapped | YARA, Sigma |
| LSASS Memory | T1003.001 | Mapped | Sigma, Behavioral |
| Security Account Manager | T1003.002 | Mapped | Sigma |
| NTDS | T1003.003 | Mapped | Sigma |
| LSA Secrets | T1003.004 | Mapped | Sigma |
| DCSync | T1003.006 | Mapped | Sigma |
| Credentials from Password Stores | T1555 | Mapped | Sigma |
| Credentials from Web Browsers | T1555.003 | Mapped | Sigma |
| Input Capture | T1056 | Mapped | Behavioral |
| Keylogging | T1056.001 | Mapped | Behavioral |
| Brute Force | T1110 | Mapped | Sigma |
| Password Spraying | T1110.003 | Mapped | Sigma |
| Adversary-in-the-Middle | T1557 | Partial | Network |
| Kerberoasting | T1558.003 | Mapped | Sigma |
| Unsecured Credentials | T1552 | Mapped | Sigma |
TA0007 - Discovery
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| Account Discovery | T1087 | Mapped | Sigma |
| Local Account | T1087.001 | Mapped | Sigma |
| Domain Account | T1087.002 | Mapped | Sigma |
| File and Directory Discovery | T1083 | Partial | Sigma |
| Process Discovery | T1057 | Partial | Sigma |
| System Information Discovery | T1082 | Mapped | Sigma |
| System Network Configuration Discovery | T1016 | Mapped | Sigma |
| System Network Connections Discovery | T1049 | Mapped | Sigma |
| Permission Groups Discovery | T1069 | Mapped | Sigma |
| Domain Trust Discovery | T1482 | Mapped | Sigma |
| Security Software Discovery | T1518.001 | Mapped | Sigma |
TA0008 - Lateral Movement
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| Remote Services | T1021 | Mapped | Sigma |
| Remote Desktop Protocol | T1021.001 | Mapped | Sigma |
| SMB/Windows Admin Shares | T1021.002 | Mapped | Sigma |
| Windows Remote Management | T1021.006 | Mapped | Sigma |
| Lateral Tool Transfer | T1570 | Mapped | Sigma |
| Taint Shared Content | T1080 | Partial | Behavioral |
| Use Alternate Authentication Material | T1550 | Mapped | Sigma |
| Pass the Hash | T1550.002 | Mapped | Sigma |
| Pass the Ticket | T1550.003 | Mapped | Sigma |
| Remote Service Session Hijacking | T1563 | Mapped | Sigma |
| RDP Hijacking | T1563.002 | Mapped | Sigma |
TA0009 - Collection
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| Archive Collected Data | T1560 | Mapped | Sigma |
| Archive via Utility | T1560.001 | Mapped | Sigma |
| Data from Local System | T1005 | Partial | Behavioral |
| Data from Network Shared Drive | T1039 | Partial | Sigma |
| Screen Capture | T1113 | Mapped | Sigma |
| Clipboard Data | T1115 | Mapped | Sigma |
| Email Collection | T1114 | Mapped | Sigma |
| Automated Collection | T1119 | Partial | Behavioral |
TA0010 - Exfiltration
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| Exfiltration Over C2 Channel | T1041 | Mapped | Sigma |
| Exfiltration Over Alternative Protocol | T1048 | Mapped | Sigma |
| Exfiltration Over Asymmetric Encrypted Channel | T1048.002 | Mapped | Sigma |
| Exfiltration Over Web Service | T1567 | Mapped | Sigma |
| Exfiltration to Cloud Storage | T1567.002 | Mapped | Sigma |
| Scheduled Transfer | T1029 | Partial | Behavioral |
| Transfer Data to Cloud Account | T1537 | Mapped | Sigma |
TA0011 - Command and Control
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| Application Layer Protocol | T1071 | Mapped | Sigma |
| Web Protocols | T1071.001 | Mapped | Sigma |
| DNS | T1071.004 | Mapped | Sigma |
| Ingress Tool Transfer | T1105 | Mapped | Sigma |
| Non-Standard Port | T1571 | Mapped | Sigma |
| Protocol Tunneling | T1572 | Mapped | Sigma |
| Proxy | T1090 | Mapped | Sigma |
| External Proxy | T1090.002 | Mapped | Sigma |
| Encrypted Channel | T1573 | Partial | Network |
| DNS Tunneling | - | Mapped | Sigma |
TA0040 - Impact
Mapping status: Partial; validation-dependent
| Technique | ID | Detection | Method |
|---|
| Data Encrypted for Impact | T1486 | Mapped | YARA, ML |
| Data Destruction | T1485 | Mapped | Sigma |
| Service Stop | T1489 | Mapped | Sigma |
| Inhibit System Recovery | T1490 | Mapped | YARA, Sigma |
| Defacement | T1491 | Partial | Sigma |
| Internal Defacement | T1491.001 | Mapped | Sigma |
| Disk Wipe | T1561 | Mapped | Sigma |
| Disk Content Wipe | T1561.001 | Mapped | Sigma |
| Resource Hijacking | T1496 | Mapped | Behavioral |
Coverage Matrix Export
ATT&CK Navigator Layer
Export a JSON layer file for the MITRE ATT&CK Navigator:
# Export Navigator layer
curl "https://api.tamandua.io/v1/mitre/navigator" \
-H "Authorization: Bearer $TOKEN" \
-o tamandua-coverage.json
The exported layer includes:
- Color-coded techniques by coverage level
- Detection counts per technique
- Comments with detection methods
Import to Navigator
- Go to ATT&CK Navigator
- Click "Open Existing Layer"
- Select "Upload from Local"
- Upload the exported JSON file
Coverage Gaps
High Priority Gaps
| Technique | ID | Reason | Remediation Plan |
|---|
| Hardware Additions | T1200 | Requires physical access monitoring | Future roadmap |
| Supply Chain: Software Dependencies | T1195.001 | Complex to detect | ML development |
| Firmware Corruption | T1495 | Low-level access required | Partnership needed |
Medium Priority Gaps
| Technique | ID | Current Status | Notes |
|---|
| Traffic Signaling | T1205 | Partial coverage | Improving network analysis |
| Rootkit | T1014 | Limited | Anti-rootkit in development |
| Browser Session Hijacking | T1185 | Partial | Browser extension planned |
Detection Quality Metrics
By Detection Method
| Method | Techniques Covered | Avg. Confidence | False Positive Rate |
|---|
| Sigma Rules | 120+ | High | Low (<5%) |
| YARA Rules | 60+ | Very High | Very Low (<2%) |
| ML Detection | 80+ | Medium-High | Medium (5-10%) |
| Behavioral | 50+ | Medium | Medium (5-15%) |
| IOC Matching | 40+ | Very High | Very Low (<1%) |
By Tactic
| Tactic | Coverage % | Detection Quality |
|---|
| Initial Access | Partial | Validation-dependent |
| Execution | Partial | Validation-dependent |
| Persistence | Partial | Validation-dependent |
| Privilege Escalation | Partial | Validation-dependent |
| Defense Evasion | Partial | Validation-dependent |
| Credential Access | Partial | Validation-dependent |
| Discovery | Partial | Validation-dependent |
| Lateral Movement | Partial | Validation-dependent |
| Collection | Partial | Validation-dependent |
| Exfiltration | Partial | Validation-dependent |
| Command and Control | Partial | Validation-dependent |
| Impact | Partial | Validation-dependent |
Coverage API
Get Coverage Summary
GET /api/v1/mitre/coverage
# Response
{
"data": {
"total_techniques": 200,
"covered_count": 150,
"active_count": 145,
"coverage_percent": 75,
"generated_at": "2025-01-15T00:00:00Z"
}
}
Get Coverage by Tactic
GET /api/v1/mitre/tactics
# Response
{
"data": [
{
"tactic": {
"id": "TA0001",
"name": "Initial Access"
},
"techniques": [...],
"covered_count": 7,
"total_count": 10,
"coverage_percent": 70
}
]
}
Get Coverage Gaps
GET /api/v1/mitre/gaps
# Response
{
"data": [
{
"technique_id": "T1200",
"technique_name": "Hardware Additions",
"tactic": "Initial Access",
"priority": "high"
}
],
"total_gaps": 25
}
Get Technique Details
GET /api/v1/mitre/technique/T1059
# Response
{
"data": {
"id": "T1059",
"name": "Command and Scripting Interpreter",
"total_detections": 1500,
"recent_detections": [...],
"trend": [...],
"severity_breakdown": {
"critical": 100,
"high": 500,
"medium": 700,
"low": 200
}
}
}
Improving Coverage
Adding Custom Rules
- Identify gaps in your environment
- Review MITRE technique documentation
- Create Sigma or YARA rules
- Test against sample data
- Deploy and monitor
Community Contributions
Tamandua accepts community rule contributions:
- Fork the rules repository
- Add new rules with MITRE mapping
- Submit pull request with test cases
- Rules reviewed by security team
Request Coverage
Report coverage gaps:
# Report a gap
tamanduactl feedback coverage-gap \
--technique T1XXX \
--description "Need detection for..."
Related Documentation