A rule mapped to MITRE is not the same as real coverage
Many organizations claim coverage for MITRE ATT&CK techniques based on the mere existence of a rule or collected data. However, true coverage requires a tuned alert that generates actionable insights for analysts. The absence of a functioning alert, even with available data, means detection relies solely on proactive hunting. A significant gap exists when organizations report having data but no effective detection mechanism.Valid Accounts (T1078) is frequently exploited using legitimate credentials, necessitating behavioral baselines beyond simple login success. Detecting Defense Evasion, such as disabling security tools or logging, presents another common and serious vulnerability. New Account Creation (T1136) events, though often logged, frequently lack proper alerting for suspicious activity outside standard administrative processes.Achieving genuine coverage demands honesty about detection capabilities. True coverage implies data availability, a working and tuned detection rule, analyst visibility, and a defined response plan. Without these elements, ATT&CK heatmaps offer a misleading visual representation of security posture. The question remains which techniques are commonly mislabeled as covered by others.