Home/Compliance/Audit answer
Audit

Compliance audit answer

For a whole framework: every control, the ATT&CK techniques it defends, and whether you can detect them
This is the one-page answer to "are my controls actually backed by detection?". For each control in the framework it shows the ATT&CK techniques the control maps to, and marks each technique detectable when a real rule (Sigma, CAR, IDS, YARA, Falco) covers it, or a gap when nothing does. Honest by construction: control-to-technique links come only from the published mappings, and a technique counts as detectable only if a real rule maps to it. Controls with no ATT&CK mapping are shown as such, not hidden. Export the full matrix for your auditor below.
10
OWASP Web controls
9
controls with ATT&CK mapping
11
distinct techniques defended
11
of those, detectable
100%
overall detection coverage
Export matrix (CSV) Export (JSON) the artifact to hand an auditor

Coverage by control family

1 families
FamilyControlsMappedTechniquesDetectableCoverage
A 10 9 11 11 100%

Control-by-control coverage

10 controls
A01:2021 Broken Access Control 3/3 detectable
A02:2021 Cryptographic Failures 2/2 detectable
A03:2021 Injection 2/2 detectable
A04:2021 Insecure Design no ATT&CK mapping
A05:2021 Security Misconfiguration 1/1 detectable
A06:2021 Vulnerable and Outdated Components 1/1 detectable
A07:2021 Identification and Authentication Failures 3/3 detectable
A08:2021 Software and Data Integrity Failures 2/2 detectable
A09:2021 Security Logging and Monitoring Failures 2/2 detectable
A10:2021 Server-Side Request Forgery (SSRF) 1/1 detectable
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin