13 min read Updated July 6, 2026

MITRE ATT&CK Coverage

Tamandua maps current and intended detections to the MITRE ATT&CK framework. Coverage is evidence-backed only where rules, telemetry, and validation runs exist.

Coverage Summary

MetricValue
Total Techniques MappedPartial; publish counts only from dated validation artifacts
Tactics MappedPartial; validation-dependent
Enterprise Matrix CoveragePartial; no percentage without a dated benchmark artifact
Sub-techniques MappedPartial; validation-dependent

Coverage by Tactic

TA0001 - Initial Access

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
PhishingT1566MappedSigma, ML
Phishing: Spearphishing AttachmentT1566.001MappedYARA, Sigma
Phishing: Spearphishing LinkT1566.002MappedSigma, IOC
Exploit Public-Facing ApplicationT1190PartialBehavioral
External Remote ServicesT1133MappedSigma
Valid AccountsT1078MappedSigma
Drive-by CompromiseT1189PartialML, YARA
Supply Chain CompromiseT1195MappedSigma

TA0002 - Execution

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
Command and Scripting InterpreterT1059MappedSigma, YARA
PowerShellT1059.001MappedSigma
Windows Command ShellT1059.003MappedSigma
Visual BasicT1059.005MappedSigma
PythonT1059.006MappedSigma
JavaScriptT1059.007MappedSigma
Scheduled Task/JobT1053MappedSigma
Scheduled TaskT1053.005MappedSigma
User ExecutionT1204MappedSigma, Behavioral
Malicious LinkT1204.001MappedSigma
Malicious FileT1204.002MappedYARA, ML
Native APIT1106MappedBehavioral
Windows Management InstrumentationT1047MappedSigma
Inter-Process CommunicationT1559PartialBehavioral
Shared ModulesT1129MappedSigma

TA0003 - Persistence

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
Boot or Logon Autostart ExecutionT1547MappedSigma
Registry Run KeysT1547.001MappedSigma
Authentication PackageT1547.002MappedSigma
Time ProvidersT1547.003MappedSigma
Winlogon Helper DLLT1547.004MappedSigma
Scheduled Task/JobT1053MappedSigma
Create AccountT1136MappedSigma
Local AccountT1136.001MappedSigma
Domain AccountT1136.002MappedSigma
Create or Modify System ProcessT1543MappedSigma
Windows ServiceT1543.003MappedSigma
Event Triggered ExecutionT1546MappedSigma
Change Default File AssociationT1546.001MappedSigma
WMI Event SubscriptionT1546.003MappedSigma
Startup ItemsT1037.005MappedSigma
BITS JobsT1197MappedSigma

TA0004 - Privilege Escalation

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
Abuse Elevation Control MechanismT1548MappedSigma
Bypass UACT1548.002MappedSigma
Access Token ManipulationT1134MappedBehavioral
Token ImpersonationT1134.001MappedBehavioral
Create Process with TokenT1134.002MappedBehavioral
Process InjectionT1055MappedBehavioral, YARA
DLL InjectionT1055.001MappedBehavioral
PE InjectionT1055.002MappedYARA
Process HollowingT1055.012MappedBehavioral
Exploitation for Privilege EscalationT1068PartialML
Valid AccountsT1078MappedSigma

TA0005 - Defense Evasion

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
Indicator RemovalT1070MappedSigma
Clear Windows Event LogsT1070.001MappedSigma
Clear Linux LogsT1070.002MappedSigma
File DeletionT1070.004MappedSigma
TimestompT1070.006MappedSigma
Impair DefensesT1562MappedSigma
Disable Windows DefenderT1562.001MappedSigma
Disable FirewallT1562.004MappedSigma
MasqueradingT1036MappedSigma, ML
Match Legitimate NameT1036.005MappedSigma
Obfuscated FilesT1027MappedYARA, ML
Binary PaddingT1027.001MappedYARA
SteganographyT1027.003PartialML
Process InjectionT1055MappedBehavioral
Signed Binary Proxy ExecutionT1218MappedSigma
CMSTPT1218.003MappedSigma
MSBuildT1218.004MappedSigma
MshtaT1218.005MappedSigma
Regsvr32T1218.010MappedSigma
Rundll32T1218.011MappedSigma
Indirect Command ExecutionT1202MappedSigma
ETW Tampering-MappedSigma
Command Line Spoofing-MappedSigma
PPID Spoofing-MappedBehavioral

TA0006 - Credential Access

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
OS Credential DumpingT1003MappedYARA, Sigma
LSASS MemoryT1003.001MappedSigma, Behavioral
Security Account ManagerT1003.002MappedSigma
NTDST1003.003MappedSigma
LSA SecretsT1003.004MappedSigma
DCSyncT1003.006MappedSigma
Credentials from Password StoresT1555MappedSigma
Credentials from Web BrowsersT1555.003MappedSigma
Input CaptureT1056MappedBehavioral
KeyloggingT1056.001MappedBehavioral
Brute ForceT1110MappedSigma
Password SprayingT1110.003MappedSigma
Adversary-in-the-MiddleT1557PartialNetwork
KerberoastingT1558.003MappedSigma
Unsecured CredentialsT1552MappedSigma

TA0007 - Discovery

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
Account DiscoveryT1087MappedSigma
Local AccountT1087.001MappedSigma
Domain AccountT1087.002MappedSigma
File and Directory DiscoveryT1083PartialSigma
Process DiscoveryT1057PartialSigma
System Information DiscoveryT1082MappedSigma
System Network Configuration DiscoveryT1016MappedSigma
System Network Connections DiscoveryT1049MappedSigma
Permission Groups DiscoveryT1069MappedSigma
Domain Trust DiscoveryT1482MappedSigma
Security Software DiscoveryT1518.001MappedSigma

TA0008 - Lateral Movement

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
Remote ServicesT1021MappedSigma
Remote Desktop ProtocolT1021.001MappedSigma
SMB/Windows Admin SharesT1021.002MappedSigma
Windows Remote ManagementT1021.006MappedSigma
Lateral Tool TransferT1570MappedSigma
Taint Shared ContentT1080PartialBehavioral
Use Alternate Authentication MaterialT1550MappedSigma
Pass the HashT1550.002MappedSigma
Pass the TicketT1550.003MappedSigma
Remote Service Session HijackingT1563MappedSigma
RDP HijackingT1563.002MappedSigma

TA0009 - Collection

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
Archive Collected DataT1560MappedSigma
Archive via UtilityT1560.001MappedSigma
Data from Local SystemT1005PartialBehavioral
Data from Network Shared DriveT1039PartialSigma
Screen CaptureT1113MappedSigma
Clipboard DataT1115MappedSigma
Email CollectionT1114MappedSigma
Automated CollectionT1119PartialBehavioral

TA0010 - Exfiltration

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
Exfiltration Over C2 ChannelT1041MappedSigma
Exfiltration Over Alternative ProtocolT1048MappedSigma
Exfiltration Over Asymmetric Encrypted ChannelT1048.002MappedSigma
Exfiltration Over Web ServiceT1567MappedSigma
Exfiltration to Cloud StorageT1567.002MappedSigma
Scheduled TransferT1029PartialBehavioral
Transfer Data to Cloud AccountT1537MappedSigma

TA0011 - Command and Control

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
Application Layer ProtocolT1071MappedSigma
Web ProtocolsT1071.001MappedSigma
DNST1071.004MappedSigma
Ingress Tool TransferT1105MappedSigma
Non-Standard PortT1571MappedSigma
Protocol TunnelingT1572MappedSigma
ProxyT1090MappedSigma
External ProxyT1090.002MappedSigma
Encrypted ChannelT1573PartialNetwork
DNS Tunneling-MappedSigma

TA0040 - Impact

Mapping status: Partial; validation-dependent
TechniqueIDDetectionMethod
Data Encrypted for ImpactT1486MappedYARA, ML
Data DestructionT1485MappedSigma
Service StopT1489MappedSigma
Inhibit System RecoveryT1490MappedYARA, Sigma
DefacementT1491PartialSigma
Internal DefacementT1491.001MappedSigma
Disk WipeT1561MappedSigma
Disk Content WipeT1561.001MappedSigma
Resource HijackingT1496MappedBehavioral

Coverage Matrix Export

ATT&CK Navigator Layer

Export a JSON layer file for the MITRE ATT&CK Navigator:

# Export Navigator layer
curl "https://api.tamandua.io/v1/mitre/navigator" \
  -H "Authorization: Bearer $TOKEN" \
  -o tamandua-coverage.json

The exported layer includes:

  • Color-coded techniques by coverage level
  • Detection counts per technique
  • Comments with detection methods

Import to Navigator

  1. Go to ATT&CK Navigator
  2. Click "Open Existing Layer"
  3. Select "Upload from Local"
  4. Upload the exported JSON file

Coverage Gaps

High Priority Gaps

TechniqueIDReasonRemediation Plan
Hardware AdditionsT1200Requires physical access monitoringFuture roadmap
Supply Chain: Software DependenciesT1195.001Complex to detectML development
Firmware CorruptionT1495Low-level access requiredPartnership needed

Medium Priority Gaps

TechniqueIDCurrent StatusNotes
Traffic SignalingT1205Partial coverageImproving network analysis
RootkitT1014LimitedAnti-rootkit in development
Browser Session HijackingT1185PartialBrowser extension planned

Detection Quality Metrics

By Detection Method

MethodTechniques CoveredAvg. ConfidenceFalse Positive Rate
Sigma Rules120+HighLow (<5%)
YARA Rules60+Very HighVery Low (<2%)
ML Detection80+Medium-HighMedium (5-10%)
Behavioral50+MediumMedium (5-15%)
IOC Matching40+Very HighVery Low (<1%)

By Tactic

TacticCoverage %Detection Quality
Initial AccessPartialValidation-dependent
ExecutionPartialValidation-dependent
PersistencePartialValidation-dependent
Privilege EscalationPartialValidation-dependent
Defense EvasionPartialValidation-dependent
Credential AccessPartialValidation-dependent
DiscoveryPartialValidation-dependent
Lateral MovementPartialValidation-dependent
CollectionPartialValidation-dependent
ExfiltrationPartialValidation-dependent
Command and ControlPartialValidation-dependent
ImpactPartialValidation-dependent

Coverage API

Get Coverage Summary

GET /api/v1/mitre/coverage

# Response
{
  "data": {
    "total_techniques": 200,
    "covered_count": 150,
    "active_count": 145,
    "coverage_percent": 75,
    "generated_at": "2025-01-15T00:00:00Z"
  }
}

Get Coverage by Tactic

GET /api/v1/mitre/tactics

# Response
{
  "data": [
    {
      "tactic": {
        "id": "TA0001",
        "name": "Initial Access"
      },
      "techniques": [...],
      "covered_count": 7,
      "total_count": 10,
      "coverage_percent": 70
    }
  ]
}

Get Coverage Gaps

GET /api/v1/mitre/gaps

# Response
{
  "data": [
    {
      "technique_id": "T1200",
      "technique_name": "Hardware Additions",
      "tactic": "Initial Access",
      "priority": "high"
    }
  ],
  "total_gaps": 25
}

Get Technique Details

GET /api/v1/mitre/technique/T1059

# Response
{
  "data": {
    "id": "T1059",
    "name": "Command and Scripting Interpreter",
    "total_detections": 1500,
    "recent_detections": [...],
    "trend": [...],
    "severity_breakdown": {
      "critical": 100,
      "high": 500,
      "medium": 700,
      "low": 200
    }
  }
}

Improving Coverage

Adding Custom Rules

  1. Identify gaps in your environment
  2. Review MITRE technique documentation
  3. Create Sigma or YARA rules
  4. Test against sample data
  5. Deploy and monitor

Community Contributions

Tamandua accepts community rule contributions:

  1. Fork the rules repository
  2. Add new rules with MITRE mapping
  3. Submit pull request with test cases
  4. Rules reviewed by security team

Request Coverage

Report coverage gaps:

# Report a gap
tamanduactl feedback coverage-gap \
  --technique T1XXX \
  --description "Need detection for..."

Related Documentation