Telemetry assurance
Telemetry assurance answers a question a rule count cannot: do you have the visibility to detect this behaviour at all? It is computed from the log sources ATT&CK's own detection analytics require, weighted by how much of your estate each source actually covers.
Why it became computable
ATT&CK v18 (October 2025) replaced the legacy data-source model with detection strategies and analytics that reference concrete log sources and channels, and v19.2 carries 1,758 of them for Enterprise. Before that, “you probably cannot see this” was a caveat. Now it is arithmetic.
423 techniques — 89% of all Windows techniques — have analytics referencing Sysmon. For 20 of them it is the only source referenced. Without it, or an EDR supplying equivalent process, command line and module telemetry, those behaviours are not under-detected. They are invisible.
The four bands
A source that would detect the behaviour covers 90% or more of the estate.
60–89%. Real coverage, but an adversary landing outside it is unobserved.
Some coverage below 60%. Detection is possible but should not be relied upon.
No source you collect would record it. No rule can change this.
A technique is banded on its best available route, because you need one working source, not all of them.
Possession is not assurance
The model asks how much of the estate each source actually covers, not whether you own the product. A source deployed on 30% of hosts is not the same capability as one deployed everywhere and healthy, and the model will not pretend otherwise. That single question usually moves an assessment more than any scoring decision.
Deception as a detection route
Deception is treated as what it is: an independent, decisive route for a bounded set of behaviours, where a single event is a true positive by construction. It raises an assurance floor rather than estate coverage — a tripwire catches whoever touches it and says nothing about anyone who does not — so it can reach partial and never assured.
Credit is placement multiplied by operationalisation. A decoy placed wherever was convenient and monitored by nobody is credited with nothing, and leaves the assurance picture identical to declaring no deception at all.
What you get out
A ranked list of what to enable, ordered by how many of your in-scope techniques each source would unblock, naming the tool class and a free route rather than a product. Plus the list of behaviours you cannot currently see, and which of them sit on a path to something you said matters.