Your ATT&CK heat map is probably lying to you

MITRE ATT&CK for Blue Teams: Map, Detect & Stop Real Attacks — Nexus Academy course

Almost every security team now has an ATT&CK heat map, and almost every heat map is greener than the truth. The reason is simple: coverage is usually assessed by asking whether a tool claims to detect a technique, rather than by testing whether it does, in this environment, with this configuration, and whether anyone would notice the alert.

Three levels of coverage, only one of which counts

  • Claimed. The vendor says the product detects it. This is marketing, not measurement.
  • Present. The telemetry exists and a rule is enabled. Better, but still untested.
  • Validated. The technique was executed in your environment, the detection fired, and it reached a human who understood it. This is the only column worth colouring green.

Start from the threat, not the matrix

Trying to cover the full matrix is a way to spend a year and improve nothing in particular. Pick the threat groups that plausibly target your sector, take the techniques they actually use, and work that shorter list to validated coverage. Depth on twenty relevant techniques beats shallow claims across three hundred.

What the v18 structure changes

ATT&CK v18 restructured detection guidance into Detection Strategies and Analytics — a more explicit model that separates the behaviour you are trying to catch from the specific analytic that catches it in a given data source. For detection engineers this is a practical improvement: it makes it obvious when you have one strategy implemented three ways, and when a technique has no strategy at all.

Emulate, then tune

Atomic Red Team gives you small, discrete tests per technique — ideal for confirming whether a single detection fires. Caldera runs chained operations that look more like an intrusion, which surfaces the gaps between detections that individually work. Run both. The first tells you whether the rule exists; the second tells you whether the story is visible.

Then do the unglamorous half: tune the false positives. A detection that fires forty times a day is functionally absent, because the analyst has learned to close it.

Report the map you can defend

A heat map with fewer green cells and a note explaining how each one was validated is a stronger artefact in front of leadership than a colourful one nobody tested. It also converts directly into a budget request, because every uncovered technique is a specific, explainable gap.

Pick five techniques this week. Run the atomic tests. Count how many detections actually fired. The number is usually instructive.

Go deeper

MITRE ATT&CK for Blue Teams: Map, Detect & Stop Real Attacks

Every vendor claims ATT&CK coverage; very few teams can show which techniques they would actually catch. This course closes that gap — mapping, detection engineering against the v18 Strategies and Analytics model, then proving it by emulation.

Enrol on UdemyCourse details

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *