Threat-informed report

owasp-mobile-2024 - threat & detection coverage

Generated 2026-06-04 12:25 UTC from TTPI engine data
This report maps owasp-mobile-2024 controls to the MITRE ATT&CK techniques they address, then checks each technique against our detection corpus (Sigma, CAR, IDS, YARA, Falco). It shows, control by control, what attacks each control is meant to stop and whether those attacks are actually detectable today. Use it as the threat-informed backbone of an audit response or pentest report.

Coverage Summary

8
threat-mapped controls
7
ATT&CK techniques addressed
5
techniques we can detect
71%
detection coverage
Coverage = of the distinct techniques mapped to this framework, the share for which we hold at least one detection rule. Gaps below list controls with zero detection coverage - the priority remediation set.

Priority Gaps - controls with no detection coverage

2
These controls map to attacker techniques we currently cannot detect. Each is a candidate for a new detection or a compensating control.
M7:2024Insufficient Binary Protections1 technique uncovered
M9:2024Insecure Data Storage1 technique uncovered

M

6/8 techniques covered
M10:2024 Insufficient Cryptography 1/1 detectable
M1:2024 Improper Credential Usage 1/1 detectable
M2:2024 Inadequate Supply Chain Security 1/1 detectable
M3:2024 Insecure Authentication/Authorization 1/1 detectable
M4:2024 Insufficient Input/Output Validation 1/1 detectable
M5:2024 Insecure Communication 1/1 detectable
M7:2024 Insufficient Binary Protections 0/1 detectable
M9:2024 Insecure Data Storage 0/1 detectable
Switch framework: NIST 800-53 · NIST CSF · CIS v8.1 · OWASP Web
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin