Skip to main content

Outcomes NavigatorOutcomes Navigator Guide

MITRE Coverage Score

Quickly understand the efficacy of your configuration in protecting against a MITRE ATT&CK® technique.[14]




[14] MITRE ATT&CK and ATT&CK are trademarks of The MITRE Corporation ("MITRE"). Exabeam is not affiliated with or sponsored or endorsed by MITRE. Nothing herein is a representation of the views or opinions of MITRE or its personnel.

The MITRE Coverage Score is a metric of how well your environment as a whole is configured to protect against an ATT&CK technique. At a glance, you can summarize the strength of your protection without analyzing the numbers and details yourself.

The MITRE Coverage Score aggregates the coverage levels of all Exabeam applications or features Outcomes Navigator assesses, including Advanced Analytics rules, Correlation Rules, and Dashboards. Your score for a given ATT&CK technique is determined by the percentage of possible parsed fields across all Exabeam applications or features that your environment actively parses:

  • Best – Your environment actively parses 75 to 100 percent of all possible parsed fields relevant to the ATT&CK technique.

  • Better – Your environment actively parses 50 to 74 percent of all possible parsed fields relevant to the ATT&CK technique.

  • Good – Your environment actively parses one to 49 percent of all possible fields relevant to the ATT&CK technique.

  • None – Your environment doesn't parse any fields relevant to the ATT&CK technique.

To determine the fields your environment actively parses across all Exabeam applications or features for a given use case, Outcomes Navigator takes the union of all possible parsed fields across Exabeam applications or features and compares it to the fields your environment actively parses for the ATT&CK technique.

The percentage is calculated by:

Equation 2. 
P=AFTF100P=\frac{AF}{TF}\cdot100


where P is the percentage, AF is the number of fields your environment actively parses across all Exabeam applications or features for the ATT&CK technique, and TF is the number of fields in the union of all possible parsed fields across Exabeam applications or features for the ATT&CK technique.

Since the MITRE Coverage Score is based on the amount and quality of data, the best way to improve your score is to configure a wider variety of relevant products and ensure the values in the logs from those products are fully extracted. Follow recommendations to improve your MITRE Coverage Score directly in Outcomes Navigator.




[14] MITRE ATT&CK and ATT&CK are trademarks of The MITRE Corporation ("MITRE"). Exabeam is not affiliated with or sponsored or endorsed by MITRE. Nothing herein is a representation of the views or opinions of MITRE or its personnel.