detection-coverage-review

Analyze detection coverage against the MITRE ATT&CK matrix to identify gaps.

6|Updated May 30, 2026
One-click install
npx skills add https://github.com/jassics/awesome-claude-security --skill detection-coverage-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: detection-coverage-review
Source: https://github.com/jassics/awesome-claude-security/tree/main/plugins/detection-engineering/skills/detection-coverage-review
Command: npx skills add https://github.com/jassics/awesome-claude-security --skill detection-coverage-review

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill helps assess detection coverage against the MITRE ATT&CK matrix, identifying tactics and techniques that are covered, partially covered, or blind.

Core Features & Use Cases

  • ATT&CK Coverage Analysis: Analyze which tactics/techniques are covered by detection rules.
  • Data Source Inventory: Map existing detections to data sources.
  • Threat Relevance Rating: Rate each technique based on data availability and threat relevance.
  • Gap Identification: Identify gaps and plan for improvements.
  • Use Case: For a SOC or program, use this Skill to find and prioritize detection gaps for enhanced security.

Quick Start

Run the detection coverage review skill to evaluate your current detection setup against the MITRE ATT&CK matrix.

Frequently Asked Questions about detection-coverage-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I analyze detection coverage against the MITRE ATT&CK matrix?

Analyzing MITRE ATT&CK detection coverage involves evaluating your current detection rules to identify which tactics and techniques are fully covered, partially covered, or completely blind spots in your security operations.

What is a detection gap analysis in cybersecurity operations?

A detection gap analysis is the process of mapping existing security detections and data sources against the MITRE ATT&CK framework to pinpoint missing visibility and prioritize threat intelligence improvements.

How do I map existing detection rules to data sources for threat relevance?

Mapping detection rules to data sources requires inventorying your current telemetry and rating each technique based on data availability and threat relevance to ensure adequate visibility.

Can I use this for a SOC program to prioritize detection improvements?

Yes, a Security Operations Center program can use MITRE ATT&CK coverage analysis to identify gaps and systematically plan improvements for enhanced threat detection capabilities.

What is the best way to identify blind spots in my threat detection setup?

The best way to identify blind spots is to evaluate your detection setup against the MITRE ATT&CK matrix, categorizing techniques as covered, partially covered, or blind.

Are there limitations when evaluating detection rules against the MITRE ATT&CK framework?

Evaluating detection rules against the MITRE ATT&CK framework is limited by the completeness of your existing data sources and the accuracy of your threat relevance ratings during the coverage analysis.