MITRE ATT&CK threat-informed defence
Threat-informed defence means deciding what to detect and block by looking at how the attackers most likely to target you actually operate. We use MITRE ATT&CK to map your current prevention and detection coverage against those behaviours, show where the blind spots are, and put the missing detections in a sensible order.
What MITRE ATT&CK is, in one paragraph
MITRE ATT&CK is a public knowledge base of attacker behaviour, built from real intrusion reporting. It breaks an attack into tactics (the goal at each stage, such as gaining access or moving between systems) and techniques (how the goal is reached, such as phishing or abusing valid accounts). It gives your analysts, your managed provider and your leadership one shared vocabulary.
Start from your adversaries, not the whole matrix
The matrix lists hundreds of techniques and sub-techniques. Covering all of them spreads effort thin, so we start from who is likely to come after you. For a Canadian organization that means the Canadian Centre for Cyber Security’s published threat assessments, sector reporting, the ransomware crews active against organizations your size, and your own incident history. The techniques those groups use become the short list.
How the coverage mapping works
For each technique on the short list we check three things. Do you collect the logs that would show it? Is there a rule that alerts on it? Has anyone proved that the rule fires?
Many coverage reports blur those together. A technique you log but never alert on gives you a forensic record, and nobody gets woken up. We explain the difference in ATT&CK coverage mapping without the heat-map theatre.
Prevention counts too. If application allowlisting stops a technique on every endpoint, a missing alert for it matters much less.
Finding blind spots and ranking detections
You get a ranked list of gaps. Each is ranked by how often your likely adversaries use the technique, how early it sits in an attack, and what a new detection would take to build and run.
A missing log source often closes several gaps at once. Turning on PowerShell script block logging, for example, can expose several techniques in one change. Those changes go to the top. Building and tuning the rules themselves is covered by SOC and SIEM detection engineering.
Mapping a real intrusion after an incident
We map what the attacker did, step by step, from the evidence your investigation produced (the forensic work sits under incident response and forensics). Where you want an alert proved rather than assumed, the technique can be emulated under written authorization as part of red teaming and adversary simulation.
What you receive
| Deliverable | What it is for |
|---|---|
| Adversary short list | The groups and techniques relevant to you, with the reasoning |
| Coverage map | Logged, alerted and tested, shown separately for each technique |
| Ranked gap list | The next detections and log sources to add, in order |
| Leadership summary | One page on what you would and would not catch today |
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
Testing and adversary simulation are carried out only with signed authorization, to a scope agreed in writing.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Do we need to cover every ATT&CK technique?
No. ATT&CK is a knowledge base of observed attacker behaviour, not a checklist to score full marks on. Some techniques cannot be detected well at all, and many will never be used against an organization like yours.
Which threat actors do you map against?
The ones with a plausible reason to target you: groups known to hit your sector and region, the ransomware operators active against organizations of your size, and anything your own incident history shows.
What access do you need?
Read access to your detection rules, alert history and log source inventory is usually enough. We do not need to run anything in your environment for the mapping itself.
Can ATT&CK help after an incident?
Yes. Mapping a real intrusion step by step to ATT&CK shows which behaviours you saw, which you missed, and which detection would have cut the attack short. It turns a painful week into a specific list of fixes.
Find out what your detections would actually catch
Tell us your sector, where your logs go, and who runs your monitoring. The reply says what a mapping would cover and what you would receive. See also all security services.