Detection coverage heatmap
407 of 697 techniques have detection coverage · 58%
Where can you actually see attacks happen, and where are you blind? Every enterprise ATT&CK technique is grouped by tactic and marked green when we hold detection content (Sigma / CAR / network-IDS / YARA / Falco) mapped to it, and red when there is no coverage - the gaps to close. Counts are honest: a technique is covered only when a real rule maps to it.