← Book contents
APPENDIX A · OPERATIONAL USE OF MITRE ATT&CK Book · edition v1.2

Appendix A - Operational Use of MITRE ATT&CK

ATT&CK is a shared vocabulary, not an operating model and not a coverage target. UTIOM turns it into capability through five steps:

Scope from the environment: intersect what you run, what you protect and who realistically targets you.

Anchor to crown jewels: model realistic attack paths to each critical asset and prioritise techniques on those paths.

Translate techniques to telemetry: measure what is actually collected and at what quality; structural blind spots are visibility gaps.

Engineer detection: normalise, version, test and trace each rule to a technique, threat model and crown jewel.

Validate with emulation: test telemetry completeness, detection timing and analyst decisions against profiled adversaries.

MetricHonest denominator
Coverage per tacticAdequately observed tactics / tactics in the scoped threat profile
Coverage per threat modelModelled attack paths with required telemetry / total modelled paths
Trace completion rateRules traceable to technique, model, crown jewel and impact / rules sampled
Detection validation rateRules tested by emulation / total live rules
MTTD per priority TTPDetection time for prioritised behaviours, not an estate-wide aggregate
Cite this chapter: Adineh, R. (2026). Appendix A - Operational Use of MITRE ATT&CK. UTIOM Framework Book, edition 1.2. utiom.de/book/appendix-a-mitre-attack/
← Back to book contents

Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →