Applied Cybernetics Group
Threat intel → detection pipeline
Tuesday, July 14, 2026
Data as of 20:11 UTC

The gap map · corpus / ATT&CK · recomputed daily

Fourteen techniques are exploited and undetected — mapped to MITRE ATT&CK, clickable to the rules

155 ATT&CK techniques carry live exploitation signal — CISA KEV CVEs (via MITRE CTID mappings), CIRCL MISP citations and active malware-family telemetry — cross-referenced against the SigmaHQ community rule index. Where signal is present and coverage is zero, the technique is a gap and enters the authoring queue. Every cell links to its technique page: the KEV CVEs, OSINT and community rules behind it. Data as of 2026-07-14.

gap — exploited, zero coverage · 14 thrunt rule shipped · 3 community-covered · 130 (luminance = signal) pre-compromise, not gap-scored · 8

The full 14-tactic matrix is best on a wider screen. Every technique — all 155, with its signal, coverage and gap state — is in the register below; the 14 gaps are marked gap.

195 cells for 155 techniques — multi-tactic techniques repeat per tactic column. States are exclusive per technique: 14 + 3 + 130 + 8 = 155. The matrix works without JavaScript — every cell is a link; the filter and detail line are enhancements.

Why the gaps hide in the long tail — coverage follows fame

The same 155 techniques, sorted by exploitation signal. Left channel: SigmaHQ community rules tagged to the technique. Right channel: thrunt's composite signal (KEV CVE mappings, MISP citations, family activity). Both share one √-scaled axis — equal length is equal count. The heaviest-signal techniques are the best-covered; the 14 gaps (red) sit in the low-signal tail, where nobody wrote a rule because the technique never made headlines.

0 1 1 10 10 50 50 100 100 150 150 ← community rules exploitation signal →

The heaviest signal

T1059 Command and Scripting Interpreter carries the corpus's top signal (170) and 94 community rules — attention tracks exploitation here.

The most-covered

T1059.001 PowerShell has 220 community rules against a signal of 2. Coverage follows fame, not risk.

Where thrunt authors

The 14 gaps are low-signal-but-exploited — the techniques the community skipped. Each is scored in the authoring queue and shipped with its intel context.

The full register 155 techniques · signal-ranked
IDTechniqueSigKEVRulesState
T1059 Command and Scripting InterpreterE 170 170 94
T1190 Exploit Public-Facing ApplicationIA 157 157 147
T1068 Exploitation for Privilege EscalationPE 69 69 30
T1005 Data from Local SystemC 47 46 14
T1078 Valid AccountsDE/P/PE/IA 46 46 55
T1203 Exploitation for Client ExecutionE 43 43 35
T1105 Ingress Tool TransferCaC 36 35 87
T1204.002 Malicious FileE 33 33 39
T1505.003 Web ShellP 26 26 34
T1133 External Remote ServicesP/IA 25 25 20
T1189 Drive-by CompromiseIA 22 21 3
T1496 Resource HijackingI 20 19 13
T1055 Process InjectionDE/PE 19 19 36
T1003 OS Credential DumpingCA 18 18 36
T1574 Hijack Execution FlowDE/E 16 16 8
T1486 Data Encrypted for ImpactI 15 15 16
T1059.004 Unix ShellE 14 14 18
T1059.007 JavaScriptE 14 14 29
T1041 Exfiltration Over C2 ChannelE 12 12 5
T1204.001 Malicious LinkE 11 11 4
T1608.001 Upload MalwareRD 11 11 0 pre
T1071.001 Web ProtocolsCaC 10 10 42
T1136 Create AccountP 10 10 3
T1555 Credentials from Password StoresCA 10 9 8
T1202 Indirect Command ExecutionDE 9 9 40
T1498 Network Denial of ServiceI 9 8 3
T1543 Create or Modify System ProcessP/PE 9 9 9
T1499 Endpoint Denial of ServiceI 8 7 3
T1046 Network Service DiscoveryD 7 7 20
T1059.003 Windows Command ShellE 7 6 46
T1082 System Information DiscoveryD 7 7 33
T1106 Native APIE 7 7 14
T1566.001 Spearphishing AttachmentIA 7 7 24
T1566.002 Spearphishing LinkIA 7 5 4 rule
T1027 Obfuscated Files or InformationDE 6 5 94
T1087 Account DiscoveryD 6 6 16
T1091 Replication Through Removable MediaLM/IA 6 6 1
T1485 Data DestructionI 6 6 20
T1566 PhishingIA 6 6 14
T1070.004 File DeletionDE 5 5 15
T1083 File and Directory DiscoveryD 5 5 24
T1087.002 Domain AccountD 5 5 21
T1003.001 LSASS MemoryCA 4 4 79
T1011 Exfiltration Over Other Network MediumE 4 4 0 gap
T1021 Remote ServicesLM 4 4 10
T1037 Boot or Logon Initialization ScriptsP/PE 4 3 0 rule
T1048 Exfiltration Over Alternative ProtocolE 4 4 12
T1112 Modify RegistryDE/P 4 4 94
T1114 Email CollectionC 4 3 4
T1210 Exploitation of Remote ServicesLM 4 4 15
T1212 Exploitation for Credential AccessCA 4 4 5
T1497 Virtualization/Sandbox EvasionDE/D 4 4 0 gap
T1548 Abuse Elevation Control MechanismPE 4 4 23
T1550.002 Pass the HashLM 4 4 5
T1552 Unsecured CredentialsCA 4 4 13
T1557 Adversary-in-the-MiddleCA/C 4 4 10
T1003.003 NTDSCA 3 3 24
T1056 Input CaptureC/CA 3 3 2
T1070 Indicator RemovalDE 3 3 20
T1090 ProxyCaC 3 3 22
T1110 Brute ForceCA 3 2 25
T1185 Browser Session HijackingC 3 3 2
T1204 User ExecutionE 3 2 10
T1221 Template InjectionDE 3 3 2
T1552.001 Credentials In FilesCA 3 3 24
T1558 Steal or Forge Kerberos TicketsCA 3 3 5
T1567 Exfiltration Over Web ServiceE 3 3 12
T1573.001 Symmetric CryptographyCaC 3 3 0 gap
T1584.005 BotnetRD 3 2 0 pre
T1611 Escape to HostPE 3 3 2
T1001 Data ObfuscationCaC 2 2 0 gap
T1018 Remote System DiscoveryD 2 2 17
T1021.001 Remote Desktop ProtocolLM 2 2 16
T1021.004 SSHLM 2 2 5
T1033 System Owner/User DiscoveryD 2 2 30
T1036 MasqueradingDE 2 2 40
T1040 Network SniffingCA/D 2 2 9
T1047 Windows Management InstrumentationE 2 2 52
IDTechniqueSigKEVRulesState
T1053 Scheduled Task/JobE/P/PE 2 2 12
T1053.005 Scheduled TaskE/P/PE 2 2 51
T1056.001 KeyloggingC/CA 2 1 3
T1059.001 PowerShellE 2 1 220
T1071 Application Layer ProtocolCaC 2 1 7
T1098 Account ManipulationP/PE 2 2 32
T1098.004 SSH Authorized KeysP/PE 2 1 0 rule
T1136.001 Local AccountP 2 2 16
T1140 Deobfuscate/Decode Files or InformationDE 2 2 18
T1195.002 Compromise Software Supply ChainIA 2 2 17
T1213 Data from Information RepositoriesC 2 2 7
T1218 System Binary Proxy ExecutionDE 2 2 153
T1219 Remote Access ToolsCaC 2 1 6
T1482 Domain Trust DiscoveryD 2 2 17
T1490 Inhibit System RecoveryI 2 2 27
T1495 Firmware CorruptionI 2 2 1
T1499.002 Service Exhaustion FloodI 2 2 0 gap
T1499.004 Application or System ExploitationI 2 2 3
T1505 Server Software ComponentP 2 2 1
T1530 Data from Cloud StorageC 2 2 0 gap
T1547 Boot or Logon Autostart ExecutionP/PE 2 1 7
T1553.005 Mark-of-the-Web BypassDE 2 2 6
T1556 Modify Authentication ProcessDE/P/CA 2 2 12
T1560.001 Archive via UtilityC 2 2 17
T1565 Data ManipulationI 2 2 3
T1565.001 Stored Data ManipulationI 2 2 6
T1588.001 MalwareRD 2 2 1 pre
T1592 Gather Victim Host InformationR 2 2 0 pre
T1622 Debugger EvasionDE/D 2 2 1
T1003.008 /etc/passwd and /etc/shadowCA 1 1 0 gap
T1007 System Service DiscoveryD 1 1 11
T1016 System Network Configuration DiscoveryD 1 1 11
T1036.005 Match Legitimate Resource Name or LocationDE 1 1 21
T1048.003 Exfiltration Over Unencrypted Non-C2 ProtocolE 1 1 9
T1049 System Network Connections DiscoveryD 1 1 9
T1055.001 Dynamic-link Library InjectionDE/PE 1 1 8
T1055.012 Process HollowingDE/PE 1 1 5
T1056.002 GUI Input CaptureC/CA 1 0 3
T1069 Permission Groups DiscoveryD 1 1 3
T1071.002 File Transfer ProtocolsCaC 1 1 0 gap
T1078.003 Local AccountsDE/P/PE/IA 1 1 5
T1078.004 Cloud AccountsDE/P/PE/IA 1 1 40
T1087.001 Local AccountD 1 1 13
T1090.001 Internal ProxyCaC 1 1 6
T1113 Screen CaptureC 1 0 10
T1114.002 Remote Email CollectionC 1 1 0 gap
T1119 Automated CollectionC 1 1 5
T1134.001 Token Impersonation/TheftDE/PE 1 1 9
T1195 Supply Chain CompromiseIA 1 1 1
T1199 Trusted RelationshipIA 1 1 1
T1211 Exploitation for StealthDE 1 1 4
T1217 Browser Information DiscoveryD 1 1 4
T1222 File and Directory Permissions ModificationDE 1 1 2
T1484.001 Group Policy ModificationDE/PE 1 1 6
T1489 Service StopI 1 1 20
T1491.002 External DefacementI 1 1 0 gap
T1498.001 Direct Network FloodI 1 1 0 gap
T1528 Steal Application Access TokenCA 1 1 14
T1531 Account Access RemovalI 1 1 9
T1542.005 TFTP BootDE/P 1 1 0 gap
T1547.001 Registry Run Keys / Startup FolderP/PE 1 1 39
T1547.009 Shortcut ModificationP/PE 1 1 4
T1548.001 Setuid and SetgidPE 1 1 2
T1548.002 Bypass User Account ControlPE 1 1 56
T1552.004 Private KeysCA 1 1 7
T1555.001 KeychainCA 1 0 1
T1557.001 Name Resolution Poisoning and SMB RelayCA/C 1 1 10
T1569.002 Service ExecutionE 1 1 43
T1570 Lateral Tool TransferLM 1 1 6
T1571 Non-Standard PortCaC 1 1 5
T1588 Obtain CapabilitiesRD 1 1 2 pre
T1588.006 VulnerabilitiesRD 1 1 0 pre
T1595 Active ScanningR 1 1 3 pre
T1598.002 Spearphishing AttachmentR 1 1 1 pre
T1601 Modify System ImageDE 1 1 0 gap
T1602 Data from Configuration RepositoryC 1 1 0 gap
T1653 Power SettingsP 1 1 1

Signal = MISP citations + KEV CVEs mapped (CTID) + active-family presence. Coverage = SigmaHQ community rules tagged to the technique. Structural exclusion: pre-compromise tactics (Reconnaissance, Resource Development) are not writable detection gaps. Source: MITRE ATT&CK & CTID mappings · CISA KEV · CIRCL MISP · SigmaHQ · 2026-07-14.