Rule counts measure what you have, not what works.
Coverage requires proving the full chain from telemetry to alert.
Validated detection coverage and detection drift are the only metrics that survive scrutiny.
"How many detections do we have deployed?" is the wrong question — and most SOCs are still building their coverage story around it.
Three hundred detection rules sounds like a strong posture until you ask the follow-up question nobody wants to ask this week: how many of them actually fire when the technique they are supposed to catch is really attempted, right now, against production telemetry?
Rule counts measure inventory. They say nothing about efficacy. A detection can exist in the SIEM, look correctly configured, and still silently fail to fire because a log source stopped forwarding, a field got renamed upstream, or the underlying technique evolved past what the rule logic anticipated. Coverage measured by rule count cannot see any of that. Coverage measured by evidence can.
Any silent break in this chain is a coverage gap — even when the rule itself is technically correct.
The shift to evidence-based coverage
The shift is simple to state and hard to operationalize without the right approach: for every technique your detection library claims to cover, safely execute that technique and record whether the expected alert actually fired — end to end, from telemetry generation through analyst-visible signal.
Map claimed coverage to ATT&CK
Not every technique matters equally to every organization. Start from the tactics and techniques your threat model actually prioritizes for your environment.
Emulate the technique safely and repeatably
The step most programs skip — because doing it manually, technique by technique, across a live environment, at a useful cadence, is not something a human red team can sustain alongside everything else.
Score the outcome against the full detection chain
A pass means the log was generated, ingested, parsed correctly, matched by the rule, and surfaced somewhere an analyst would see it. A failure anywhere in that chain is a coverage gap.
Track results over time, not just once
A single validation run tells you today's state. A trend line tells you whether coverage is improving, holding steady, or quietly eroding as the environment changes underneath it.
Summary: inventory vs. evidence
| Dimension | Inventory-based coverage | Evidence-driven coverage |
|---|---|---|
| Primary question | How many detection rules exist? | Which attacker behaviors produced actionable alerts? |
| Proof source | Rule catalogs, mappings, and assumptions. | Safe technique emulation, telemetry results, and alert outcomes. |
| Failure visibility | Low visibility into broken telemetry, parsing, routing, or rule drift. | Clear visibility into where the detection chain failed. |
| Operating model | Point-in-time reviews and manual checks. | Continuous validation with repeatable evidence capture. |
| Executive value | Shows security activity. | Shows coverage proof, risk reduction, and remediation progress. |
The metrics that matter
Two numbers describe reality instead of inventory. Together they replace the rule count on every executive slide.
The percentage of in-scope techniques confirmed to produce an actionable alert this week. The number that survives a board question, an audit, and an incident post-mortem.
The same approach supports attack path validation and reachability-driven prioritization. When teams understand not only whether a detection exists, but whether a realistic path can reach the exposed condition and produce evidence, detection coverage becomes a governed security outcome instead of a reporting artifact.
Detection coverage maturity assessment
Use the following levels to evaluate whether detection coverage is still operating as an inventory exercise or has matured into a repeatable, evidence-driven validation function. Each level should be supported by recorded outcomes, not assumptions.
Rules cataloged, coverage claimed
Detection rules are cataloged, ownership is assigned, and claimed coverage is mapped to the relevant ATT&CK tactics and techniques for the environment.
Priority techniques tested on a schedule
Priority techniques are validated through scheduled, safe emulation exercises, with results reviewed by detection engineering and SOC leadership.
End-to-end outcomes captured on cadence
Safe technique emulation runs on a recurring cadence, detection outcomes are captured end to end, and failures are linked to specific telemetry, parsing, rule logic, or alert routing gaps.
Regressions trigger remediation
Previously validated detections are re-tested continuously, detection drift is tracked over time, and regressions trigger remediation workflows before coverage assumptions become stale.
Structured evidence for executives and auditors
Coverage proof, detection drift, remediation history, and risk acceptance decisions are available as structured evidence for executives, auditors, and incident reviews.
A mature program should be able to show which techniques are covered, which were safely emulated, which alerts fired, which controls failed, and how quickly each gap was corrected. This is the practical difference between a coverage claim and a coverage proof.
Glossary of terms
A security operating model that relies on recorded validation outcomes instead of assumptions, inventories, or static claims.
The structured record of tests, observations, logs, alerts, failures, and remediation history used to prove whether controls work.
The percentage of relevant techniques proven to generate actionable alerts during safe validation.
The regression of previously validated detections due to environment, telemetry, parsing, logic, or routing changes.
Recurring, repeatable testing that confirms controls continue to operate as environments and attacker behaviors change.
The process of proving whether realistic attacker paths are reachable and whether controls respond as expected along those paths.
A prioritization method that focuses remediation on exposures that can realistically be reached and exploited in context.
See validated detection coverage on your environment.
Hayrok emulates ATT&CK techniques safely and continuously, records the full detection chain, and reports two numbers your board can actually stand behind.
Mira Latham · Hayrok's Bumblebee
Practical guidance for evidence-driven security validation. Field notes from the hive on how modern SOCs move from rule counts to validated coverage.