Define the technique detection coverage

  • リリースバージョン: Australia
  • 更新日 2026年03月12日
  • 所要時間:4分
  • Define the technique detection coverage that your organization must measure and detect specific adversary techniques.

    始める前に

    • Role required: sn_ti.admin, sn_si.admin: write access
    • Role required: sn_ti.read: read access

    このタスクについて

    The technique coverage definitions are used in the overall technique detection mapping. You can use the base system technique coverage. The base system technique coverage consists of coverage types None, Poor, Fair, Good, Very Good, and Excellent. The base system technique coverage is also associated with pre-defined colors. You can customize the coverage type entries and colors, or create your own entries. For example, you can modify the base system coverage types to Not Applicable, Partial Coverage, and Complete Coverage. Alternatively, you can also create numerical measures for the coverage types such as 0-25 percent, 25–50 percent, and 50–100 percent. The type of modifications done to the base system coverage are not limited to the examples shared.

    The customizations that you make to the coverage type and color are used in the overall technique detection mapping and also in the heat map.

    注:
    If you modify the base system coverage definition, the Coverage Type icons do not display with the techniques in the heat map. The heat map works as expected when you modify the same fields as the base system's-defined technique detection coverage and coverage colors. However, if you delete existing fields from the overall technique detection coverage, the heat map does not display the coverage type icons.

    Coverage type symbols are not displayed if you modify the coverage definition.

    手順

    1. Navigate to All > Threat Intelligence > MITRE ATT&CK Administration > Detection Coverage Definition.
    2. Review the overall technique detection entries and customize the entries for your environment.
      表 : 1. Detection Coverage Definition
      Field Description
      Overall Technique Detection Coverage Name of the overall technique detection coverage. The base system technique coverage consists of None, Poor, Fair, Good, Very Good, or Excellent.
      Coverage Color Color that is assigned to the detection coverage score. The color that you define is used for the technique detection coverage in the heat map.

      You can customize the colors using HEX codes and RGB(A) values.

      Description Overall technique detection coverage. See the base system definition in the Scoring Definition.

      The following illustration shows the Detection Coverage Definition list.

      Define the technique coverage.
    3. To add an entry, click New, complete the entries, and click Submit.