primedefence

MITRE ATT&CK coverage in the SOC

How to use MITRE ATT&CK in a SOC-CMM assessment: coverage, detection validation, threat modelling and operational evidence from the 2026 report.

Wide lattice of small glass cells in perspective with scattered clusters glowing royal blue, like a coverage matrix

ATT&CK coverage is growing, but coverage is not enough

The 2026 SOC-CMM report shows a clear increase in MITRE ATT&CK coverage: the average rises from 45% to 60%. That improvement matters, but the report also cautions that coverage must be compared with targets and context. A high percentage does not prove the SOC detects real threats, and not every framework technique is relevant or technically observable for every organization.

What an assessment should review

ATT&CK is useful for threat modelling, detection engineering and defensive gap analysis. In SOC-CMM, maturity appears when the map is connected to data sources, use cases, validation, operations and continuous improvement.

ElementExpected evidenceCommon error
CoverageRelevant technique matrix, target and status.Counting techniques without defining relevance.
TelemetryData sources that make behavior observable.Marking coverage without enough data.
DetectionsRules, logic, owner and review cycle.Creating rules nobody maintains.
ValidationPre-production tests, purple teaming or event generation.Assuming a rule works because it exists.

Detection validation is the bridge

The report treats detection validation as an activity that creates operational trust in detection capability. It can include pre-production tests, exercises, simulation, purple teaming, event injection or ingestion monitoring. The mature question is not how many rules exist, but which ones have been tested and under what conditions.

Improvement roadmap

A defensible roadmap prioritizes techniques by risk, exposure, available sources and operational value. It also separates telemetry gaps, logic gaps, validation gaps and process gaps. This prevents ATT&CK from becoming a decorative table.

  • Define relevant techniques by threat and critical service.
  • Map data sources and ingestion quality.
  • Prioritize detections by risk and feasibility.
  • Validate rules with controlled tests.
  • Review coverage as part of the SOC improvement cycle.

Minimum telemetry required to claim coverage

A technique is not covered just because a rule has its tag. There must be a source observing the behavior, maintained logic, an owner, a test and a review criterion. Without that chain, ATT&CK describes intent, not operational capability.

LayerControl questionTypical gap
SourceDo we have enough data to observe the technique?Logs not enabled or insufficient retention.
LogicDoes detection identify behavior, not only brittle indicators?Rules copied without environment adaptation.
ValidationWas it tested with real, simulated or purple-team events?Coverage claimed without testing.
OperationDoes the analyst know triage, severity and response?Detection without runbook or handover.

Frequently asked questions

Independent by design

Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

Independent SOC-CMM assessment