Campaign-Level Detection Coverage
Why I moved away from flat rule counts and towards campaign paths, telemetry, and the gaps between them.
Reading notes
I found graph-based approaches more useful than flat rule inventories for representing detection coverage. They make the relationships between campaign stages, telemetry, rules, and controls visible.
The most useful distinction is between technique-level evaluation and campaign-level evaluation. A detection may work for one behaviour while a campaign still passes through several unobserved stages.
Design consequence
The coverage model should report where a campaign can progress without reliable visibility, not only how many ATT&CK techniques have associated rules. That makes the result easier to prioritise and connects naturally to current campaign information from ThreatWatch.