Home/Compliance/Audit answer
Audit

Compliance audit answer

For a whole framework: every control, the ATT&CK techniques it defends, and whether you can detect them
This is the one-page answer to "are my controls actually backed by detection?". For each control in the framework it shows the ATT&CK techniques the control maps to, and marks each technique detectable when a real rule (Sigma, CAR, IDS, YARA, Falco) covers it, or a gap when nothing does. Honest by construction: control-to-technique links come only from the published mappings, and a technique counts as detectable only if a real rule maps to it. Controls with no ATT&CK mapping are shown as such, not hidden. Export the full matrix for your auditor below.
10
OWASP API controls
7
controls with ATT&CK mapping
5
distinct techniques defended
5
of those, detectable
100%
overall detection coverage
Export matrix (CSV) Export (JSON) the artifact to hand an auditor

Coverage by control family

1 families
FamilyControlsMappedTechniquesDetectableCoverage
A 10 7 5 5 100%

Control-by-control coverage

10 controls
API10:2023 Unsafe Consumption of APIs 1/1 detectable
API1:2023 Broken Object Level Authorization 1/1 detectable
API2:2023 Broken Authentication 2/2 detectable
API3:2023 Broken Object Property Level Authorization no ATT&CK mapping
API4:2023 Unrestricted Resource Consumption 1/1 detectable
API5:2023 Broken Function Level Authorization 1/1 detectable
API6:2023 Unrestricted Access to Sensitive Business Flows no ATT&CK mapping
API7:2023 Server Side Request Forgery 1/1 detectable
API8:2023 Security Misconfiguration 1/1 detectable
API9:2023 Improper Inventory Management no ATT&CK mapping
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin