ATT&CK is a shared vocabulary, not an operating model and not a coverage target. UTIOM turns it into capability through five steps:
Scope from the environment: intersect what you run, what you protect and who realistically targets you.
Anchor to crown jewels: model realistic attack paths to each critical asset and prioritise techniques on those paths.
Translate techniques to telemetry: measure what is actually collected and at what quality; structural blind spots are visibility gaps.
Engineer detection: normalise, version, test and trace each rule to a technique, threat model and crown jewel.
Validate with emulation: test telemetry completeness, detection timing and analyst decisions against profiled adversaries.
| Metric | Honest denominator |
|---|---|
| Coverage per tactic | Adequately observed tactics / tactics in the scoped threat profile |
| Coverage per threat model | Modelled attack paths with required telemetry / total modelled paths |
| Trace completion rate | Rules traceable to technique, model, crown jewel and impact / rules sampled |
| Detection validation rate | Rules tested by emulation / total live rules |
| MTTD per priority TTP | Detection time for prioritised behaviours, not an estate-wide aggregate |
Adineh, R. (2026). Appendix A - Operational Use of MITRE ATT&CK. UTIOM Framework
Book, edition 1.2. utiom.de/book/appendix-a-mitre-attack/