Microsoft Sentinel
Cloud and workloads

View MITRE ATT&CK Coverage in Microsoft Sentinel

In brief

The Microsoft Sentinel MITRE ATT&CK coverage article has updated wording, navigation instructions, and references for filtering scenarios and viewing technique details.

What Defender admins need to know

Administrators can use the revised guidance when reviewing MITRE coverage and related analytics or hunting content.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: View MITRE ATT&CK coverageCoverage in Microsoft Sentinel description: View your organization's MITRE ATT&CK coverage in Microsoft Sentinel. Identify active detections and available rules to strengthen security. author: mberdugo ms.topic: how-to ms.date: 06/16/202507/01/2026 ms.author: monaberdugo appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal ms.custom: sfi-image-nochange, msecd-doc-authoring-10121016 ai-usage: ai-assisted

#Customer intent: As a security analyst, I want to use the MITRE ATT&CK framework in Microsoft Sentinel so that I can assess and enhance my organization's threat detection and response capabilities.

MITRE ATT&CK is a publicly accessible knowledge base of tactics and techniques commonly used by attackers. It's created and maintained based on real-world observations. Many organizations use the MITRE ATT&CK knowledge base to develop specific threat models and methodologies to verify security status in their environments.

Microsoft Sentinel analyzes ingested data, not only to detect threats with built-in analytics and help you investigate incidents, but also to visualize the nature and coverage of your organization's security status.

This article describes how to use the MITRE page in Microsoft Sentinel to view the analytics rules (detections) already active in your workspace and the detections available for you to configure. Use this page to understand your organization's security coverage based on the tactics and techniques from the MITRE ATT&CK framework.

Prerequisites

Microsoft Sentinel is currently aligned to The MITRE ATT&CK framework, version 18.

View current MITRE coverage

By default, both currently active scheduled query and near real-time (NRT) rules are indicated in the coverage matrix.

:::image type="content" source="media/mitre-coverage/mitre-coverage-defender.png" alt-text="Screenshot of the MITRE ATT&CK page in the Defender portal." lightbox="media/mitre-coverage/mitre-coverage-defender.png":::

To filter the page by a specific threat scenario, toggle the **View MITRE by threat scenario** option on, and then select a threat scenario from the drop-down menu. The page is updated accordingly.updates to show MITRE coverage for the selected threat scenario. For example:

:::image type="content" source="media/mitre-coverage/mitre-by-threat-scenario.png" alt-text="Screenshot of the MITRE ATT&CK page filtered by a specific threat scenario.":::


- **Use the search bar** to search for a specific technique in the matrix, using the technique name or ID, to view your organization's security status for the selected technique.

- **Select a specific technique** in the matrix to view more details in the details pane. There,In the details pane, use the links to jump to any of the following locations:

    - In the **Description** area, select **View full technique details ...** for more information about the selected technique in the MITRE ATT&CK framework knowledge base.

    - Scroll down in the pane and select links to any of the active items to jump to the relevant area in Microsoft Sentinel.

    For example, select **Hunting queries** to jump to the **Hunting** page. There,On the **Hunting** page, you see a filtered list of the hunting queries that are associated with the selected technique, and available for you to configure in your workspace.

On the Defender portal, the details pane also shows recommended coverage details, including the ratio of active detections and security services (products) out of all recommended detections and services for the selected technique.
  1. In Microsoft Sentinel, under Threat management, select MITRE ATT&CK (Preview), and then select items in the Simulated rules menu to simulate your organization's possible security status.

  2. Use the coverage matrix elements as you would otherwiselegend, search bar, and technique selection described in View current MITRE coverage to view the simulated coverage for a specific technique.

Use the MITRE ATT&CK framework in analytics rules and incidents

  • Threat hunting:

    • When you're creating a new hunting query, select the specific tactics and techniques to apply to your query.

    • When searching for active hunting queries, filter the queries displayed by tactics by selecting an item from the list above the grid. Select a query to see tactic and technique details in the details pane on the side.

    • When you're creating bookmarks, either use the technique mapping inherited from the hunting query, or create your own mapping.

    For more information, see Hunt for threats with Microsoft Sentinel and Keep track of data during hunting with Microsoft Sentinel.

  • Related content

    For more information, see: