Proposal
Detection coverage (MITRE ATT&CK)
We run real attack techniques in your environment, controlled and agreed in advance, and record what your detection saw, what it merely logged and what it missed entirely. The result is a map technique by technique, and only what was actually executed goes into it: coverage claimed in a vendor datasheet stays out.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
Detection coverage (MITRE ATT&CK)
The detection has been bought. What is missing is knowing what it covers.
How we run it
What this work consists of
We execute real attack techniques in your environment, in a controlled and agreed way, and record three answers for each one: what your detection saw and alerted on, what it only wrote to a log, and what went unnoticed. The result is a technique-by-technique map, grounded in MITRE ATT&CK.
Only what was actually executed goes on the map. Coverage claimed in vendor documentation stays out, because a promise is not detection. The chosen scope defines the reach: you can start with the techniques most used by the groups active in your sector, run the full chain from initial access to the objective, or turn the measurement into cycles that retest the deployed rules and show the evolution side by side.
Before executing, we survey what telemetry exists, where it comes from, and how long it is retained, because a technique without a data source is not detectable by any tool. We need an agreed window and approval to run in the environment. You receive the coverage map, the gaps in risk order and, depending on scope, the proposed detection rules and the cycle-over-cycle comparison.
How we conduct it, stage by stage
Telemetry survey
Before talking about rules, we survey what records exist, where they come from and how long they are kept. A technique with no data source cannot be detected by any tool.
Controlled execution
We execute the techniques in your environment, in an agreed window, and record step by step what the detection saw, what it merely logged and what it missed.
Coverage analysis
We compare expected detection with observed detection and order the gaps by risk, with the rules proposed to close each one.
Presentation
A meeting with leadership translating the technical result into business risk and investment decisions. We arrive with the answers to the questions the board always asks: what to attack first, how much effort it takes and what happens if nothing is done.
What is not included
- Deploying or replacing detection tools: this work measures what exists, it does not swap what is installed
- Operating the monitoring, which is its own ongoing service
- Tuning the rules in your products, which stays with whoever operates the tool
- Deploying the proposed detection rules: we deliver them on paper, and whoever operates puts them live
- Fixing gaps that stem from configuration or architecture rather than detection rules
- Executing techniques outside the agreed window or without approval from whoever operates the environment
- Any accreditation by MITRE, which does not accredit or endorse vendors
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.