MITRE ATT&CK Coverage — Threadlinqs Intelligence

MITRE ATT&CK is the industry catalogue of adversary tactics and techniques. This page maps the Threadlinqs corpus onto it: for every tactic, how many distinct techniques the corpus documents and how many profiled threats use them, each linked to deployable Splunk SPL, Microsoft KQL and Sigma detections.

Data as of : 788 MITRE ATT&CK techniques plus 38 MITRE ATLAS (adversarial-ML) techniques observed across the corpus, 826 distinct techniques in total. Tactic labels are normalised across the Enterprise, ICS, Mobile and ATLAS matrices, so each tactic is counted once.

TacticTechniquesThreats
Defense Evasion1682,032
Persistence941,703
Collection681,806
Credential Access651,762
Execution612,007
Impact611,394
Discovery591,840
Initial Access562,128
Command and Control561,799
Privilege Escalation56988
Resource Development491,552
Reconnaissance40924
Lateral Movement27940
Exfiltration261,369
Inhibit Response Function (ICS)1212
Impact (ICS)62
Impair Process Control (ICS)59
Evasion (ICS)56
AI Attack Staging (ATLAS)45
AI Model Access (ATLAS)25
Impact (ATLAS)22
Initial Access (ICS)22
Lateral Movement (ICS)22
Collection (Mobile)21
Command and Control (Mobile)11
Defense Evasion (ATLAS)11
Discovery (ICS)11
Discovery (Mobile)11
Execution (ICS)11
Initial Access (Mobile)11
Network Effects (Mobile)11
Persistence (ATLAS)11
Persistence (ICS)11
Unmapped / non-ATT&CK921,256

What this coverage means

The deepest technique coverage sits in Defense Evasion, Persistence, Collection — the tactics where the corpus documents the most distinct adversary behaviours.

By breadth of threats affected the order changes: Initial Access, Defense Evasion, Execution appear on more profiled threats than any other tactic.

The widest divergence between the two is Initial Access: 56 distinct techniques, ranking 8 by technique depth, yet 2,128 threats, ranking 1 by breadth — a small technique set that recurs across a large share of the corpus.

Interactive matrix with per-technique detections in the app. Gap analysis and technique prediction via the MCP server. Corpus-wide counts: platform statistics.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats