Calculating a detection’s efficacy
Mean time to detect, discussed earlier in this chapter, provides a historical view of the effectiveness against attacks performed against the organization. We will group additional efficacy metrics into three areas: low-fidelity coverage, automated validations, and high-fidelity coverage. When we refer to coverage, we are talking about a measure of how much of the potential attack space can be detected. The attack space is defined by what you are trying to measure. It could be a single technique or multiple MITRE ATT&CK matrixes. We’ll start by looking at some low-fidelity methods of determining coverage.
Low-fidelity coverage metrics
A common low-fidelity coverage visualization is mapping your detections to a MITRE ATT&CK matrix, as shown in Figure 11.7. Each technique is colored according to the number of detections that have been created for it. This visualization is easy to produce, and many tools will automatically...