TID-CMM Threat-Informed Detection Capability Maturity Model
HomeModelRelationship to ATT&CK

How TID-CMM uses MITRE ATT&CK

ATT&CK is consumed, not reproduced. Every coverage claim is anchored to technique and sub-technique IDs at Enterprise v19.2, and the model's job is to decide which of those 697 techniques are worth your attention — not to encourage covering all of them.

Why covering all of ATT&CK is not the goal

ATT&CK is a catalogue of behaviour observed across all sectors and platforms. It was never a requirements list. Of the 697 techniques in Enterprise v19.2, 475 are sub-techniques, and techniques are not comparable units of work — so summing them into a percentage produces a number that looks precise and means very little.

Attempting full coverage is not ambition. It is the absence of scoping.

How the in-scope set is derived

Scope is an intersection of three things, and a technique must satisfy all three:

  1. Your platforms. A technique that only affects macOS is out of scope for an estate with no Macs, and the model says so rather than leaving it to inflate the denominator.
  2. Your adversaries. Techniques used by the groups, campaigns, malware and tools you prioritised, drawn from ATT&CK's own actor data.
  3. Your attack paths. Techniques that sit on a modelled route to something worth taking.

Techniques satisfying all three are Tier A — the set worth being excellent at. Path-only is Tier B, actor-only is Tier C. A typical result is 150 to 250 techniques rather than 697.

What ATT&CK changed, and why it matters

ATT&CK v18, released in October 2025, replaced per-technique detection prose with detection strategies and analytics that reference concrete log sources and channels, and deprecated the legacy data sources entirely. v19.2 carries that model forward at 697 detection strategies and 1,758 analytics for Enterprise.

That is the change that makes telemetry assurance computable rather than rhetorical: for a given technique the model can name the specific channels an analytic requires, compare them against what you declared you collect, and report the technique as assured, partial, weak or blind.

How telemetry assurance is computed.

The datasets

The derived datasets are published so the derivation can be checked rather than trusted: techniques with tactics and platforms, 1,057 actors with the techniques each uses, 1,745 analytics with their required log sources, and a telemetry catalogue describing how to enable each source. Download them or read them as JSON.

Why 1,745 and not 1,758. MITRE publishes 1,758 analytics for ATT&CK Enterprise v19.2. The extract carries 1,745 of them — every analytic that resolves to a technique in the active v19.2 Enterprise technique set. The 13 remaining — 0.7% — are still being reconciled against the source STIX bundle, and the dataset will be regenerated for the next release once the cause is established. Stated here rather than rounded away, because a coverage figure whose denominator is unexplained is the exact failure this model was built to expose.

Attribution. MITRE ATT&CK® is a registered trademark of The MITRE Corporation. ATT&CK content is © The MITRE Corporation and used under the ATT&CK Terms of Use. This project is not affiliated with or endorsed by MITRE.