#detectioncoverage

Claus Cramon Houmannclaushoumann
2026-01-21

@timb_machine One day when we read links like br0k3nlab.com/resources/axioms people will have read the white paper and realized how it changes the conversation about but this day was not today.

Claus Cramon Houmannclaushoumann
2025-12-10

Despite the promising title of this blog post by John Vester 'Why the MITRE ATT&CK Framework Actually Works', its a load of crock.

You can't and shouldn't use MITRE &CK to prove any sort of detection coverage or 'strong points'. At best, you can prove total absence in certain subtechniques.

If you want to do any sort of data driven you need -> there's no way around it.

levelup.gitconnected.com/why-t

ATT&CK is still ♥️ 😍 tho.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst