detection-coverage-analysis

Analyze security detection coverage against MITRE ATT&CK using Sigma, Splunk, and Elastic rules.

471|74|Updated Jan 13, 2026
One-click install
npx skills add https://github.com/MHaggis/Security-Detections-MCP --skill detection-coverage-analysis
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: detection-coverage-analysis
Source: https://github.com/MHaggis/Security-Detections-MCP/tree/main/.claude/skills/coverage-analysis
Command: npx skills add https://github.com/MHaggis/Security-Detections-MCP --skill detection-coverage-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams understand their existing detection coverage against known adversary techniques and identify gaps.

Core Features & Use Cases

  • Coverage Statistics: Get percentage-based coverage metrics for different MITRE ATT&CK tactics.
  • Gap Identification: Pinpoint specific techniques or threat profiles (like ransomware or APTs) that lack adequate detection.
  • Detection Suggestions: Receive recommendations for new detections based on missing coverage or required data sources.
  • Navigator Layer Generation: Create importable MITRE ATT&CK Navigator layers directly from your detection rules.

Quick Start

Use the detection-coverage-analysis skill to get coverage stats for elastic detections.

Frequently Asked Questions about detection-coverage-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify detection coverage gaps against the MITRE ATT&CK framework?

To identify detection coverage gaps against the MITRE ATT&CK framework, this analysis evaluates your Sigma, Splunk, and Elastic rules to pinpoint specific techniques or threat profiles like ransomware or APTs that lack adequate detection.

Can I generate a MITRE ATT&CK Navigator layer from my existing detection rules?

Yes, you can generate importable MITRE ATT&CK Navigator layers directly from your existing Sigma, Splunk, and Elastic detection rules to visually map your current security coverage across adversary techniques.

Does this analysis work with Splunk and Elastic security detections?

Yes, this analysis works with Splunk and Elastic security detections, alongside Sigma rules, analyzing them against the MITRE ATT&CK framework to provide percentage-based coverage statistics and identify missing security controls.

What is the best way to get percentage-based coverage metrics for MITRE ATT&CK tactics?

The best way to get percentage-based coverage metrics for MITRE ATT&CK tactics is to analyze your detection rules using this skill, which returns coverage statistics and metadata efficiently via server-side processing.

How do I find new detections needed for ransomware or APT threat profiles?

To find new detections needed for ransomware or APT threat profiles, this analysis identifies missing coverage across your rules and suggests new detections based on the required data sources you lack.

Why does my detection coverage analysis return metadata instead of full detection objects?

Your detection coverage analysis returns metadata instead of full detection objects because the skill utilizes efficient server-side processing to provide statistics and gap analysis without the overhead of transferring large detection payloads.