- Get Started with Outcomes Navigator
- Use Outcomes Navigator with the MITRE ATT&CK® Framework
- Use Outcomes Navigator with the Threat Detection, Investigation, and Response (TDIR) Use Case Categories Framework
- Use Outcomes Navigator for Compliance
- Use Outcomes Navigator with the OWASP Top 10 for Agentic Applications Framework
- View Recommendations for Improving Your Configuration
- Share Information in Outcomes Navigator
- Outcomes Navigator Coverage Calculation
- The Role of Parsed Fields in Coverage Calculation
- Prerequisites for Calculating Coverage
- Types of Coverage Scores
- Use Case Coverage Score
- MITRE Coverage Score
- Compliance Framework Coverage Score
- Control Coverage Score
- OWASP Agentic AI Coverage Score
- OWASP Risk Coverage Score
- Advanced Analytics Rules Coverage Calculation
- Correlation Rules Coverage Calculation
- Dashboards Coverage Calculation
- Coverage Over Time Calculation
- Outcomes Navigator Parser Calibration Tier Average Calculation
Correlation Rules Coverage Calculation
Learn how Outcomes Navigator calculates Correlation Rules coverage for a use case, MITRE ATT&CK® technique, OWASP Top 10 for Agentic Applications security risk, or compliance control.
Correlation Rules coverage is a metric of how well your environment is configured so correlation rules can detect a use case, ATT&CK technique, or OWASP Top 10 for Agentic Applications security risk, or meet the requirements of a compliance control. At a glance, you can summarize the strength of correlation rules detection without analyzing the numbers and details yourself.[18]
Defining Satisfied Rules
To calculate Correlation Rules coverage for a use case, ATT&CK technique, OWASP Top 10 for Agentic Applications security risk, or compliance control, Outcomes Navigator uses correlation rules that have all fields they require to trigger, also called satisfied rules.
Outcomes Navigator uses satisfied rules because a rule triggers only if it can evaluate all required fields; if the rule only evaluates some fields and not others, the rule doesn't trigger and, by definition, doesn't have coverage.
A rule is considered satisfied for a given use case if it meets two conditions:
All required fields were actively parsed in the past 30 days
All required fields are relevant to the use case or ATT&CK technique
Correlation rules declare which fields are required in their conditions. An internal service maps your default and custom correlation rules to use cases, ATT&CK techniques, and compliance controls.
Calculating the Score
Your Correlation Rules coverage score for each use case, ATT&CK technique, OWASP Top 10 for Agentic Applications security risk, or compliance control is the percentage of satisfied correlation rules out of all correlation rules.
The percentage is calculated by:
where P is the percentage, SR is the number of satisfied rules, and ER is the total number of enabled correlation rules.
Important Considerations
When calculating Correlation Rules coverage, Outcomes Navigator correctly considers 98 to 99 percent of all default and custom correlation rules. The remaining two to one percent of correlation rules, including rules whose rule expressions include session-end or sequence-end events, currently provide an approximate sense of coverage.
[18] MITRE ATT&CK and ATT&CK are trademarks of The MITRE Corporation ("MITRE"). Exabeam is not affiliated with or sponsored or endorsed by MITRE. Nothing herein is a representation of the views or opinions of MITRE or its personnel.