Home/Compliance/Audit answer
Audit

Compliance audit answer

For a whole framework: every control, the ATT&CK techniques it defends, and whether you can detect them
This is the one-page answer to "are my controls actually backed by detection?". For each control in the framework it shows the ATT&CK techniques the control maps to, and marks each technique detectable when a real rule (Sigma, CAR, IDS, YARA, Falco) covers it, or a gap when nothing does. Honest by construction: control-to-technique links come only from the published mappings, and a technique counts as detectable only if a real rule maps to it. Controls with no ATT&CK mapping are shown as such, not hidden. Export the full matrix for your auditor below.
10
OWASP Mobile controls
8
controls with ATT&CK mapping
7
distinct techniques defended
5
of those, detectable
71%
overall detection coverage
Export matrix (CSV) Export (JSON) the artifact to hand an auditor

Coverage by control family

1 families
FamilyControlsMappedTechniquesDetectableCoverage
M 10 8 7 5 71%

Control-by-control coverage

10 controls
M10:2024 Insufficient Cryptography 1/1 detectable
M1:2024 Improper Credential Usage 1/1 detectable
M2:2024 Inadequate Supply Chain Security 1/1 detectable
M3:2024 Insecure Authentication/Authorization 1/1 detectable
M4:2024 Insufficient Input/Output Validation 1/1 detectable
M5:2024 Insecure Communication 1/1 detectable
M6:2024 Inadequate Privacy Controls no ATT&CK mapping
M7:2024 Insufficient Binary Protections 0/1 detectable
M8:2024 Security Misconfiguration no ATT&CK mapping
M9:2024 Insecure Data Storage 0/1 detectable
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin