MITRE ATT&CK v19.1 · NIS2 · DORA · ISO 27001

Stop mapping
ATT&CK by hand.

Generate SIEM-ready detection use cases in minutes — aligned to your sector, your threat landscape, and your compliance obligations.

Generate use cases free See how it works
14
ATT&CK Tactics
All enterprise tactics · v19.1
6
SIEM platforms
Sentinel · Splunk · Elastic · Chronicle · QRadar · Sigma
11
Sectors covered
Financial Services to OT / ICS / SCADA
<3 min
Time to use case
Intake to deployable detection rule
How it works

Five steps.
One deployable use case.

Built around the workflow of a working SOC analyst — not a product manager's idea of one.

01
Define your environment
Select your sector, infrastructure stack, and crown jewels. No freeform text — structured intake that produces structured output.
02
Select tactic and technique
Choose the ATT&CK tactic or drill down to a specific technique. Technique counts and descriptions pulled live from ATT&CK v19.1.
03
Confirm your detection scope
Review every selection in a structured summary before committing. Edit any dimension without starting over.
04
Generate detection use cases
ATT&CK-aligned, sector-enriched detection logic. Sigma, KQL, SPL, EQL — ready to deploy into your SIEM.
coveragehq.nl
Step 1 of 5 — Environment
Tell us about your environment
Healthcare
Financial
Government
Energy
OT / ICS
Other
Environments
On-premises
Cloud
Windows / AD
Step 2 of 5 — Tactic
Select ATT&CK technique
TA0001 · Initial Access · 8 techniques
T1190 Exploit Public-Facing T1078 Valid Accounts
TA0003 · Persistence · 19 techniques
T1053 Scheduled Task T1136 Create Account
Step 5 of 5 — Review
Review your detection scope
Sector
Healthcare
Technique
T1190
Output
1 USE CASEFREE
Step 5 of 5 — Results
2 detection use cases generated
Exploitation of Public-Facing Application — Citrix / FortiGate / Pulse
T1190HIGH
Ransomware Mass File Encryption — OT/IT Systems
T1486CRITICAL
title: Perimeter Exploitation — Citrix
tags:
  - attack.t1190
  - attack.initial_access
Sample output

What a use case looks like.

Every use case ships with detection logic for multiple SIEM platforms, enumerated log sources, and a curated false positive register.

Exploitation of Public-Facing Application on Energy Sector Perimeter Devices (Citrix / FortiGate / Pulse)
T1190 INITIAL ACCESS HIGH
Signed PDF — Pro+
Description

Detects exploitation attempts against internet-exposed perimeter appliances commonly targeted in energy sector ransomware campaigns, including Citrix NetScaler, Fortinet FortiGate, and Ivanti Pulse Secure. Threat actors including LockBit 3.0 have leveraged CVE-2023-4966, CVE-2023-27997, and CVE-2024-21887 to gain initial access.

Log sources
Fortinet FortiGate Citrix NetScaler / ADC Ivanti Pulse Secure VPN IIS / Apache Web Server WAF Logs (F5, Imperva) Syslog (OT/IT DMZ)
Sigma
Sentinel KQL
Splunk SPL
Elastic EQL
title: Perimeter Device Exploitation — Citrix/FortiGate/Pulse status: experimental author: CoverageHQ tags: - attack.initial_access - attack.t1190 - cve.2023.4966 logsource: category: webserver detection: selection: cs-uri-stem|contains: - '/vpns/portal/scripts/' - '/dana-na/' - '/+CSCOE+/' condition: selection # references: cisa.gov/known-exploited-vulnerabilities-catalog
Frameworks & coverage

Built on the standards
your auditors expect.

MITRE ATT&CK v19.1
All 14 enterprise tactics. Technique IDs embedded in every generated rule and visible throughout the workflow.
NIS2 Directive
Annex I obligations mapped across all supported sectors. Use cases tagged to relevant NIS2 control areas.
DORA
Digital Operational Resilience Act requirements for financial sector entities, including Article 10 detection obligations.
ISO 27001 / BIO2
Detection controls cross-referenced to ISO 27001 Annex A and BIO2 baseline for Dutch government entities.
Sigma· Microsoft Sentinel KQL· Splunk SPL· Elastic EQL· QRadar AQL· Chronicle YARA-L· NCSC-NL· ENISA· CISA· Caldera v5.1.0
From the team

Detection engineering
in practice.

Pricing

Start free.
Scale when it matters.

No feature walls on the core workflow. Upgrade when you need volume or PDF export.

Free
0
always free
  • 5 use cases per month
  • All 14 ATT&CK tactics
  • KQL · SPL · EQL · Sigma
  • PDF export with watermark
  • Priority support
Get started free
Team
199
per month · excl. VAT
  • Unlimited use cases
  • All 14 ATT&CK tactics
  • KQL · SPL · EQL · Sigma
  • Signed PDF — no watermark
  • Team management
Upgrade to Team
Enterprise
MSSP & white-label
Unlimited generation · white-label branding · dedicated support · SLA available · volume pricing
Contact us

"I built this because every engagement started the same way — pulling up ATT&CK, searching for relevant techniques, manually writing detection logic for a SIEM that wasn't the same as last week's client.

CoverageHQ is the tool I needed in those sessions. Sector-aware. Threat-informed. SIEM-agnostic. Built by someone who has sat in the SOC, not someone who has read about it."