Developing and prioritizing a detection engineering backlog based on MITRE ATT&CK
ID: 0a462558-e9ac-5691-add6-291a9c17f5da
STIX ID: report--0a462558-e9ac-5691-add6-291a9c17f5da
Feed Name: Securelist by Kaspersky
Date Published: 2024-07-09
Date Updated: 2026-04-29
Author: Roman Nazarov, Andrey Tamoykin, Kaspersky Security Services
This report provides a practical framework for SOCs to prioritize detection logic by mapping available data sources to MITRE ATT&CK techniques, scoring source quality and visibility with DeTT&CT, and combining these with technique prevalence to rank detection opportunities. It details steps to inventory and assess data sources, visualize coverage in ATT&CK Navigator, calculate weighted visibility scores, and merge with attacker usage to produce a prioritized detection backlog, while highlighting limitations of historical frequency data and offering extensions for maturity, such as grouping by detection domain, attack stage, and improving source coverage and quality.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
