MITRE ATT&CK Coverage — Threadlinqs Intelligence

MITRE ATT&CK is the industry catalogue of adversary tactics and techniques. This page maps the Threadlinqs corpus onto it: for every tactic, how many distinct techniques the corpus documents and how many profiled threats use them, each linked to deployable Splunk SPL, Microsoft KQL and Sigma detections.

Data as of : 805 MITRE ATT&CK techniques plus 44 MITRE ATLAS (adversarial-ML) techniques observed across the corpus, 849 distinct techniques in total. Tactic labels are normalised across the Enterprise, ICS, Mobile and ATLAS matrices, so each tactic is counted once.

TacticTechniquesThreats
Stealth (formerly Defense Evasion)1552,221
Persistence931,818
Credential Access641,906
Execution602,207
Collection591,907
Discovery561,928
Resource Development531,709
Privilege Escalation531,023
Impact521,485
Command and Control431,907
Reconnaissance43998
Defense Impairment411,099
Initial Access362,292
Defense Evasion (Mobile)3262
Exfiltration261,410
Lateral Movement241,002
Collection (Mobile)2162
Command and Control (Mobile)1556
Initial Access (Mobile)1376
Impact (Mobile)1321
Inhibit Response Function (ICS)1315
Impact (ICS)1210
Discovery (Mobile)1144
Initial Access (ICS)1115
Credential Access (Mobile)1034
Impair Process Control (ICS)911
Persistence (Mobile)831
Collection (ICS)87
Execution (ICS)86
Persistence (ICS)77
Lateral Movement (ICS)67
Evasion (ICS)56
Discovery (ICS)55
Exfiltration (Mobile)427
Execution (Mobile)420
AI Attack Staging (ATLAS)47
Network Effects (Mobile)44
Privilege Escalation (ICS)42
Privilege Escalation (Mobile)332
AI Model Access (ATLAS)37
Command and Control (ICS)34
Lateral Movement (Mobile)32
Impact (ATLAS)22
Defense Evasion (ATLAS)11
Persistence (ATLAS)11

What this coverage means

The deepest technique coverage sits in Stealth (formerly Defense Evasion), Persistence, Credential Access — the tactics where the corpus documents the most distinct adversary behaviours.

By breadth of threats affected the order changes: Initial Access, Stealth (formerly Defense Evasion), Execution appear on more profiled threats than any other tactic.

The widest divergence between the two is Privilege Escalation (Mobile): 3 distinct techniques, ranking 39 by technique depth, yet 32 threats, ranking 22 by breadth — a small technique set that recurs across a large share of the corpus.

Interactive matrix with per-technique detections in the app. Gap analysis and technique prediction via the MCP server. Corpus-wide counts: platform statistics.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats