# Detections coverage of ATT&CK documentation

**URL:** <https://discuss.elastic.co/t/detections-coverage-of-att-ck-documentation/269692>\
**Category:** Elastic Security\
**Created:** [April 9, 2021, 9:55am UTC](https://discuss.elastic.co/t/detections-coverage-of-att-ck-documentation/269692 "2021-04-09T09:55:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [April 9, 2021, 9:55am UTC](https://discuss.elastic.co/t/detections-coverage-of-att-ck-documentation/269692/1 "2021-04-09T09:55:52Z")

</div>

Hi,

We are trying to review the ATT&CK coverage for the current detections to help us with creation and coverage of our own ruleset, is there anything available for us to use?

Thanks

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [April 12, 2021, 8:16pm UTC](https://discuss.elastic.co/t/detections-coverage-of-att-ck-documentation/269692/2 "2021-04-12T20:16:59Z")

</div>

Hey there @probson 👋

Thanks to the recent efforts of [@Thorben](https://github.com/ThorbenJ) there is the new [Elastic Security: Detection Rules ATT&CK Navigator layer generator](https://github.com/ElasticSA/elsec_dr2an) that you can use to generate an `ATT&CK Navigator` to better understand the coverage of your own rulesets. 🎉

[Here's an example navigator](https://ela.st/tj-mitre-an) detailing the coverage of the prebuilt Elastic Detection Rules shipped with the app:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/8/f85e1af413744bb1457509fb08b1c8f64c5a7a84.png)

This should cover exactly what you're looking for, but if you have any trouble/feedback please do feel free to add it to this thread (or open an issue in that repo). 🙂

Hope this helps -- cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [April 13, 2021, 8:24am UTC](https://discuss.elastic.co/t/detections-coverage-of-att-ck-documentation/269692/3 "2021-04-13T08:24:17Z")

</div>

@spong

That looks perfect thank you and thanks @Thorben, will hopefully use it in the next few days

Thanks

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [April 15, 2021, 5:57pm UTC](https://discuss.elastic.co/t/detections-coverage-of-att-ck-documentation/269692/4 "2021-04-15T17:57:24Z")

</div>

You can actually see the coverage in this table:

[Analytic Coverage Comparison | MITRE Cyber Analytics Repository](https://car.mitre.org/coverage/)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2021, 5:57pm UTC](https://discuss.elastic.co/t/detections-coverage-of-att-ck-documentation/269692/5 "2021-05-13T17:57:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
