ATK Research · 9 September 2026

Our library declares evidence for 84 techniques. Our bench can witness 18 of them.

This is a per-technique evidence map, published because a per-technique verdict is only meaningful next to the sensor set that produced it. The same technique reads covered in one estate and unknown in another, and nothing in a coverage percentage tells you which one you are looking at.

84
ATT&CK techniques in the library
186
scenario stages carrying a technique
18
techniques the bench can witness
66
still unknown, and we say why

Two columns, deliberately

Every row below carries two verdicts, and the distance between them is the point.

VerdictWhat the library declaresWhat this bench can verify
Essential80
Substitutable41
Complementary7217
Still unknown066

The four verdicts are not ours. They come from a public exchange with Reza Adineh, author of TID-CMM, who proposed splitting evidence per technique into essential, substitutable, complementary or still unknown, and observed that a bench can contribute evidence within that scope without establishing a universal ratio across techniques. We are contributing within exactly that scope. The framework is his; the measurement is ours; neither claims the other.

Method

Every scenario in the library declares, per stage, a MITRE technique and the data source its detection reads. We took the 186 stages that carry a technique, collapsed them to 84 unique techniques, and classified each one twice.

Column one — what the library declares. A technique whose stages read only network-class sources (network, dns, proxy, ics_protocol) is essential: within this library there is no non-network path to it. A technique with both a network-class and a host-class stage is substitutable. A technique with no network-class stage at all is complementary. This is design intent, recoverable from source, and it is not a measurement.

Column two — what this bench can verify. The bench is one Ubuntu 22.04 host with a Wazuh agent. No Sysmon. No commercial EDR. No Zeek, no Suricata, no NetFlow. No cloud. It therefore collects two of the classes the library uses, and a technique whose evidence never reaches it stays still unknown — not uncovered, and not covered.

What the gap says

The library's most-used evidence class is sysmon, at 68 of 186 stages. This bench runs Linux and has no Sysmon, so the single largest body of declared evidence is one it cannot witness at all. That is why 66 techniques stay unknown, and it is a fact about the bench rather than about the library or about the techniques.

Read the other way: a per-technique verdict is a property of an estate, not of a technique. Two organisations running the same library against the same 84 techniques will produce different maps, and both maps can be honest. Anyone publishing a single universal ratio is publishing a property of their own sensor set without saying so.

Limits, stated here rather than in a footnote

One library, one bench, one point in time. Column one is read from source and is therefore a statement about how the library was written, not about whether the detection works. Column two is bounded by the sensor set above and by nothing else — a richer estate moves rows out of still unknown in both directions. Substitutable in particular cannot be proven from source at all: proving that a host signal satisfies the same detection requirement as a network signal takes a run, and this table does not contain one. We publish the list and the raw data so that any of this can be recomputed or contradicted.

The full list

84 rows. Technique links go to attack.mitre.org. Sigma column shows the first two rule names the library attaches, where it attaches any.

TechniqueData sources declaredLibraryThis benchSigma rules
T0831historian, ics_protocolSubstitutableStill unknownt0831
T0836historianComplementaryStill unknown
T0843otComplementaryStill unknown
T1003.001edr, sysmonComplementaryStill unknownproc_access_lsass_dump, proc_access_win_lsass_mimikatz
T1003.003sysmonComplementaryStill unknownt1003.003
T1003.006authComplementaryComplementarywin_dcsync_replication, win_security_dcsync
T1018process, sysmonComplementaryComplementaryremote_system_discovery, t1018
T1021.001authComplementaryComplementaryinternal_rdp_lateral, t1021.001
T1021.002auth, sysmonComplementaryComplementarypsexec_service_creation, t1021.002
T1027sysmonComplementaryStill unknownproc_creation_win_powershell_obfuscation
T1041networkEssentialStill unknownnet_exfil_over_c2, net_exfil_over_c2_large_upload
T1046auth, networkSubstitutableSubstitutablelin_ssh_invalid_protocol, net_internal_port_scan
T1047sysmonComplementaryStill unknownproc_creation_win_wmic_process_creation
T1048.003dnsEssentialStill unknowndns_exfiltration_high_volume
T1053.005sysmonComplementaryStill unknownproc_creation_win_schtasks_creation, schtasks_creation_persistence
T1055.001sysmonComplementaryStill unknownsysmon_createremotethread_loadlibrary
T1056.001edrComplementaryStill unknownkeylogger_hook_behavior
T1059.001sysmonComplementaryStill unknownproc_creation_win_iis_susp_child_powershell, proc_creation_win_office_spawn_powershell
T1059.004edrComplementaryStill unknownproc_creation_lnx_shell_susp_rev_shells
T1059.005sysmonComplementaryStill unknownproc_creation_win_office_susp_macro
T1068sysmonComplementaryStill unknownwin_byovd_vulnerable_driver_load
T1069.002sysmonComplementaryStill unknowndomain_group_recon
T1070.001sysmonComplementaryStill unknownproc_creation_win_wevtutil_clear_logs, t1070.001
T1071.001networkEssentialStill unknownnet_beacon_ja3, net_cobaltstrike_beacon_ja3
T1071.004dnsEssentialStill unknowndns_tunneling_high_entropy
T1074.001[0 KHAI], sysmonComplementaryStill unknownfile_staging_mass_copy
T1078authComplementaryComplementaryt1078, win_auth_anomalous_valid_account
T1078.004azuread, cloud_audit, cloudtrailComplementaryStill unknowncloud_anomalous_console_login, t1078.004
T1087.002sysmonComplementaryStill unknownldap_recon_sharphound
T1090sysmonComplementaryStill unknownt1090
T1098cloudtrailComplementaryStill unknown
T1098.001azuread, cloud_auditComplementaryStill unknownt1098.001
T1098.005cloud_auditComplementaryStill unknownt1098.005
T1105networkEssentialStill unknownnet_tool_transfer_ingress, proc_creation_lnx_susp_curl_download
T1110.001active-response, authComplementaryComplementarylin_auth_ssh_bruteforce, win_auth_rdp_bruteforce
T1110.003authComplementaryComplementaryt1110.003, win_security_password_spray
T1114.002cloud_audit, m365ComplementaryStill unknownt1114.002
T1133authComplementaryComplementaryt1133
T1134.001sysmonComplementaryStill unknownproc_creation_win_potato_seimpersonate
T1190networkEssentialStill unknownt1190, web_exchange_proxylogon
T1204.002[0 KHAI], mailComplementaryStill unknownfile_event_win_office_maldoc_open
T1207authComplementaryComplementarywin_rogue_dc_dcshadow
T1213cloud_auditComplementaryStill unknowncloud_info_repo_bulk_download
T1219sysmonComplementaryStill unknownproc_creation_win_remote_access_tool
T1482sysmonComplementaryStill unknowndomain_trust_discovery
T1484.001authComplementaryComplementarywin_gpo_modification
T1485sysmonComplementaryStill unknownfile_mass_overwrite_delete, t1485
T1486edrComplementaryStill unknownfile_mass_encryption, t1486
T1489sysmonComplementaryStill unknownservice_stop_backup, service_stop_critical
T1490sysmonComplementaryStill unknownt1490
T1491.001sysmonComplementaryStill unknownfile_mod_webroot_index
T1496networkEssentialStill unknownnet_stratum_mining_pool
T1505.003edr, sysmonComplementaryStill unknownfile_event_win_exchange_webshell_drop, web_shell_drop_iis
T1528azuread, cloud_auditComplementaryStill unknownt1528
T1529sysmonComplementaryStill unknownt1529
T1530cloud_audit, cloudtrailComplementaryStill unknowncloud_storage_mass_object_access
T1539cloud_auditComplementaryStill unknowncloud_stolen_session_cookie, t1539
T1543.003sysmonComplementaryStill unknownwin_new_service_creation
T1546.003sysmonComplementaryStill unknownsysmon_wmi_event_subscription
T1547.001sysmonComplementaryStill unknownreg_persistence_run_key, registry_run_key_persistence
T1548.002sysmonComplementaryStill unknownproc_creation_win_uac_bypass_fodhelper, registry_uac_bypass_fodhelper
T1550.002authComplementaryComplementarypass_the_hash_ntlm
T1550.003authComplementaryComplementarypass_the_ticket_kerberos
T1552.004processComplementaryComplementaryt1552.004
T1558.001authComplementaryComplementary
T1558.003authComplementaryComplementarywin_kerberoasting_tgs, win_security_kerberoasting_4769
T1558.004authComplementaryComplementarywin_security_asreproast_4768
T1560.001sysmonComplementaryStill unknownproc_creation_win_7z_rar_password_archive
T1561.002sysmonComplementaryStill unknownraw_disk_write_mbr, t1561.002
T1562.001sysmonComplementaryStill unknownproc_creation_win_powershell_set_mppreference, t1562.001
T1564.008m365ComplementaryStill unknown
T1565.001sysmonComplementaryStill unknowndb_stored_data_tamper
T1566.001mailComplementaryStill unknownmail_phishing_link, t1566.001
T1566.002m365, proxySubstitutableStill unknownphish_credential_harvest_url
T1567.002cloudtrail, networkSubstitutableStill unknownnet_exfil_cloud_rclone, net_exfil_cloud_storage
T1570sysmonComplementaryStill unknownlateral_tool_transfer_smb
T1573.002networkEssentialStill unknownnet_malleable_c2_profile
T1574.009sysmonComplementaryStill unknownfile_event_win_unquoted_service_path, proc_creation_win_wmic_service_discovery
T1606.002authComplementaryComplementaryt1606.002
T1610kubernetesComplementaryStill unknown
T1611falcoComplementaryStill unknown
T1613kubernetesComplementaryStill unknown
T1621cloud_auditComplementaryStill unknowncloud_mfa_push_fatigue, t1621
T1648cloud_auditComplementaryStill unknowncloud_serverless_malicious_function

Raw data

Published rather than available on request, so every number above is recomputable:

ATK New Technology · Hanoi, Vietnam · Dong Nguyen · dongnx@atkvn.com

Related, same terms: Detection Reality Index Vol.1 · Vol.2 (IBM QRadar) · Vol.3 · Crypto Reality Index Vol.1 · IETF PQ authentication position paper · atkvn.com