MITRE ATT&CK Coverage — Threadlinqs Intelligence
MITRE ATT&CK is the industry catalogue of adversary tactics and techniques. This page maps the Threadlinqs corpus onto it: for every tactic, how many distinct techniques the corpus documents and how many profiled threats use them, each linked to deployable Splunk SPL, Microsoft KQL and Sigma detections.
Data as of : 805 MITRE ATT&CK techniques plus 44 MITRE ATLAS (adversarial-ML) techniques observed across the corpus, 849 distinct techniques in total. Tactic labels are normalised across the Enterprise, ICS, Mobile and ATLAS matrices, so each tactic is counted once.
| Tactic | Techniques | Threats |
|---|---|---|
| Stealth (formerly Defense Evasion) | 155 | 2,221 |
| Persistence | 93 | 1,818 |
| Credential Access | 64 | 1,906 |
| Execution | 60 | 2,207 |
| Collection | 59 | 1,907 |
| Discovery | 56 | 1,928 |
| Resource Development | 53 | 1,709 |
| Privilege Escalation | 53 | 1,023 |
| Impact | 52 | 1,485 |
| Command and Control | 43 | 1,907 |
| Reconnaissance | 43 | 998 |
| Defense Impairment | 41 | 1,099 |
| Initial Access | 36 | 2,292 |
| Defense Evasion (Mobile) | 32 | 62 |
| Exfiltration | 26 | 1,410 |
| Lateral Movement | 24 | 1,002 |
| Collection (Mobile) | 21 | 62 |
| Command and Control (Mobile) | 15 | 56 |
| Initial Access (Mobile) | 13 | 76 |
| Impact (Mobile) | 13 | 21 |
| Inhibit Response Function (ICS) | 13 | 15 |
| Impact (ICS) | 12 | 10 |
| Discovery (Mobile) | 11 | 44 |
| Initial Access (ICS) | 11 | 15 |
| Credential Access (Mobile) | 10 | 34 |
| Impair Process Control (ICS) | 9 | 11 |
| Persistence (Mobile) | 8 | 31 |
| Collection (ICS) | 8 | 7 |
| Execution (ICS) | 8 | 6 |
| Persistence (ICS) | 7 | 7 |
| Lateral Movement (ICS) | 6 | 7 |
| Evasion (ICS) | 5 | 6 |
| Discovery (ICS) | 5 | 5 |
| Exfiltration (Mobile) | 4 | 27 |
| Execution (Mobile) | 4 | 20 |
| AI Attack Staging (ATLAS) | 4 | 7 |
| Network Effects (Mobile) | 4 | 4 |
| Privilege Escalation (ICS) | 4 | 2 |
| Privilege Escalation (Mobile) | 3 | 32 |
| AI Model Access (ATLAS) | 3 | 7 |
| Command and Control (ICS) | 3 | 4 |
| Lateral Movement (Mobile) | 3 | 2 |
| Impact (ATLAS) | 2 | 2 |
| Defense Evasion (ATLAS) | 1 | 1 |
| Persistence (ATLAS) | 1 | 1 |
What this coverage means
The deepest technique coverage sits in Stealth (formerly Defense Evasion), Persistence, Credential Access — the tactics where the corpus documents the most distinct adversary behaviours.
By breadth of threats affected the order changes: Initial Access, Stealth (formerly Defense Evasion), Execution appear on more profiled threats than any other tactic.
The widest divergence between the two is Privilege Escalation (Mobile): 3 distinct techniques, ranking 39 by technique depth, yet 32 threats, ranking 22 by breadth — a small technique set that recurs across a large share of the corpus.
Interactive matrix with per-technique detections in the app. Gap analysis and technique prediction via the MCP server. Corpus-wide counts: platform statistics.
Threadlinqs Intelligence — Real-Time Threat Detection Platform
Live intelligence console
Threat weather, live.
Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.
Every threat in the corpus, newest first.