MITRE ATT&CK Coverage Heatmap

Turn your detection mappings into a coverage heatmap across the ATT&CK matrix, so the gaps are a picture rather than a spreadsheet.

Runs locally

Everything happens in your browser. What you paste or drop here is never uploaded, logged or stored.

Use the tool

Drop Sigma rules, a coverage CSV or a Navigator layer
Files are read in your browser. Mix types freely - evidence is combined.

See where detection is thin

Feed the heatmap what you have. That can be your Sigma rules, whose attack.t#### tags are read and whose status is respected, so experimental rules count as partial. It can be a simple CSV of technique, kind and source, or a Navigator layer. It lays every current ATT&CK Enterprise technique out by tactic and colours each one by the evidence behind it:

  • strong: two or more detections;
  • covered: one detection;
  • partial: experimental or narrow rules;
  • visibility: you have the telemetry, but nothing alerts on it;
  • gap: nothing at all.

A parent technique shows the best level of its sub-techniques, with a count of how many of them are covered.

Read the caveat before the colours

A green cell means a rule exists that is tagged with the technique, not that the technique would be caught. Rules can be mis-tagged, depend on logs you are not collecting, or match only one of many procedures for a technique. Treat the heatmap as a map of where to test, not a scorecard. Validate coverage with purple-team exercises and replayed telemetry, and weigh gaps by the threats relevant to you rather than aiming for an all-green chart.

Exports

Download the heatmap as a PNG for a report. You can also export a Navigator layer with scores 0 to 3 and the sources in each comment, or a CSV of every technique with its level, counts and sources. The gap list is exported separately so it can become a backlog.

Frequently asked questions

Which ATT&CK version is used?

The Enterprise release bundled with the page, shown above the grid. Revoked ids in your rules are mapped to their replacements, and a note is shown for each one.

Are my detection rules uploaded?

No. Your ruleset reveals exactly what you can and cannot see, so it is processed only in this browser tab.

Why do percentages count parent techniques only?

Counting sub-techniques as well would weight techniques with many sub-techniques more heavily. Sub-technique detail is shown in each cell and in the CSV.

References

© The MITRE Corporation. ATT&CK data is reproduced and distributed with the permission of The MITRE Corporation.

What this tool can and cannot tell you. It reports what is present in the input you provide. It cannot see anything you did not give it, and a clean result means nothing was found in that input - not that the wider system is secure.

Security guidance here follows current published sources - OWASP, MDN, the relevant RFCs, NIST, CISA, FIRST and MITRE - which are linked beside the specific claims they support.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.