D8 · CySA+

What is ATT&CK mapping in detection?

ATT&CK mapping documents which techniques you can detect vs. which are gaps — creating a "coverage heat map" to prioritize detection engineering investments.
ATT&CK Navigator visualizes detection coverage. Map existing detections to techniques → identify gaps → write new detection rules to fill gaps. Purple team exercises validate coverage in practice, not just on paper.
← Back to Glossary Practice Questions →