The gap map · corpus / ATT&CK · recomputed daily
Fourteen techniques are exploited and undetected — mapped to MITRE ATT&CK, clickable to the rules
155 ATT&CK techniques carry live exploitation signal — CISA KEV CVEs (via MITRE CTID mappings), CIRCL MISP citations and active malware-family telemetry — cross-referenced against the SigmaHQ community rule index. Where signal is present and coverage is zero, the technique is a gap and enters the authoring queue. Every cell links to its technique page: the KEV CVEs, OSINT and community rules behind it. Data as of 2026-07-14.
The full 14-tactic matrix is best on a wider screen. Every technique — all 155, with its signal, coverage and gap state — is in the register below; the 14 gaps are marked gap.
195 cells for 155 techniques — multi-tactic techniques repeat per tactic column. States are exclusive per technique: 14 + 3 + 130 + 8 = 155. The matrix works without JavaScript — every cell is a link; the filter and detail line are enhancements.
Why the gaps hide in the long tail — coverage follows fame
The same 155 techniques, sorted by exploitation signal. Left channel: SigmaHQ community rules tagged to the technique. Right channel: thrunt's composite signal (KEV CVE mappings, MISP citations, family activity). Both share one √-scaled axis — equal length is equal count. The heaviest-signal techniques are the best-covered; the 14 gaps (red) sit in the low-signal tail, where nobody wrote a rule because the technique never made headlines.
The heaviest signal
T1059 Command and Scripting Interpreter carries the corpus's top signal (170) and 94 community rules — attention tracks exploitation here.
The most-covered
T1059.001 PowerShell has 220 community rules against a signal of 2. Coverage follows fame, not risk.
Where thrunt authors
The 14 gaps are low-signal-but-exploited — the techniques the community skipped. Each is scored in the authoring queue and shipped with its intel context.
| ID | Technique | Sig | KEV | Rules | State |
|---|---|---|---|---|---|
| T1059 | Command and Scripting InterpreterE | 170 | 170 | 94 | |
| T1190 | Exploit Public-Facing ApplicationIA | 157 | 157 | 147 | |
| T1068 | Exploitation for Privilege EscalationPE | 69 | 69 | 30 | |
| T1005 | Data from Local SystemC | 47 | 46 | 14 | |
| T1078 | Valid AccountsDE/P/PE/IA | 46 | 46 | 55 | |
| T1203 | Exploitation for Client ExecutionE | 43 | 43 | 35 | |
| T1105 | Ingress Tool TransferCaC | 36 | 35 | 87 | |
| T1204.002 | Malicious FileE | 33 | 33 | 39 | |
| T1505.003 | Web ShellP | 26 | 26 | 34 | |
| T1133 | External Remote ServicesP/IA | 25 | 25 | 20 | |
| T1189 | Drive-by CompromiseIA | 22 | 21 | 3 | |
| T1496 | Resource HijackingI | 20 | 19 | 13 | |
| T1055 | Process InjectionDE/PE | 19 | 19 | 36 | |
| T1003 | OS Credential DumpingCA | 18 | 18 | 36 | |
| T1574 | Hijack Execution FlowDE/E | 16 | 16 | 8 | |
| T1486 | Data Encrypted for ImpactI | 15 | 15 | 16 | |
| T1059.004 | Unix ShellE | 14 | 14 | 18 | |
| T1059.007 | JavaScriptE | 14 | 14 | 29 | |
| T1041 | Exfiltration Over C2 ChannelE | 12 | 12 | 5 | |
| T1204.001 | Malicious LinkE | 11 | 11 | 4 | |
| T1608.001 | Upload MalwareRD | 11 | 11 | 0 | pre |
| T1071.001 | Web ProtocolsCaC | 10 | 10 | 42 | |
| T1136 | Create AccountP | 10 | 10 | 3 | |
| T1555 | Credentials from Password StoresCA | 10 | 9 | 8 | |
| T1202 | Indirect Command ExecutionDE | 9 | 9 | 40 | |
| T1498 | Network Denial of ServiceI | 9 | 8 | 3 | |
| T1543 | Create or Modify System ProcessP/PE | 9 | 9 | 9 | |
| T1499 | Endpoint Denial of ServiceI | 8 | 7 | 3 | |
| T1046 | Network Service DiscoveryD | 7 | 7 | 20 | |
| T1059.003 | Windows Command ShellE | 7 | 6 | 46 | |
| T1082 | System Information DiscoveryD | 7 | 7 | 33 | |
| T1106 | Native APIE | 7 | 7 | 14 | |
| T1566.001 | Spearphishing AttachmentIA | 7 | 7 | 24 | |
| T1566.002 | Spearphishing LinkIA | 7 | 5 | 4 | rule |
| T1027 | Obfuscated Files or InformationDE | 6 | 5 | 94 | |
| T1087 | Account DiscoveryD | 6 | 6 | 16 | |
| T1091 | Replication Through Removable MediaLM/IA | 6 | 6 | 1 | |
| T1485 | Data DestructionI | 6 | 6 | 20 | |
| T1566 | PhishingIA | 6 | 6 | 14 | |
| T1070.004 | File DeletionDE | 5 | 5 | 15 | |
| T1083 | File and Directory DiscoveryD | 5 | 5 | 24 | |
| T1087.002 | Domain AccountD | 5 | 5 | 21 | |
| T1003.001 | LSASS MemoryCA | 4 | 4 | 79 | |
| T1011 | Exfiltration Over Other Network MediumE | 4 | 4 | 0 | gap |
| T1021 | Remote ServicesLM | 4 | 4 | 10 | |
| T1037 | Boot or Logon Initialization ScriptsP/PE | 4 | 3 | 0 | rule |
| T1048 | Exfiltration Over Alternative ProtocolE | 4 | 4 | 12 | |
| T1112 | Modify RegistryDE/P | 4 | 4 | 94 | |
| T1114 | Email CollectionC | 4 | 3 | 4 | |
| T1210 | Exploitation of Remote ServicesLM | 4 | 4 | 15 | |
| T1212 | Exploitation for Credential AccessCA | 4 | 4 | 5 | |
| T1497 | Virtualization/Sandbox EvasionDE/D | 4 | 4 | 0 | gap |
| T1548 | Abuse Elevation Control MechanismPE | 4 | 4 | 23 | |
| T1550.002 | Pass the HashLM | 4 | 4 | 5 | |
| T1552 | Unsecured CredentialsCA | 4 | 4 | 13 | |
| T1557 | Adversary-in-the-MiddleCA/C | 4 | 4 | 10 | |
| T1003.003 | NTDSCA | 3 | 3 | 24 | |
| T1056 | Input CaptureC/CA | 3 | 3 | 2 | |
| T1070 | Indicator RemovalDE | 3 | 3 | 20 | |
| T1090 | ProxyCaC | 3 | 3 | 22 | |
| T1110 | Brute ForceCA | 3 | 2 | 25 | |
| T1185 | Browser Session HijackingC | 3 | 3 | 2 | |
| T1204 | User ExecutionE | 3 | 2 | 10 | |
| T1221 | Template InjectionDE | 3 | 3 | 2 | |
| T1552.001 | Credentials In FilesCA | 3 | 3 | 24 | |
| T1558 | Steal or Forge Kerberos TicketsCA | 3 | 3 | 5 | |
| T1567 | Exfiltration Over Web ServiceE | 3 | 3 | 12 | |
| T1573.001 | Symmetric CryptographyCaC | 3 | 3 | 0 | gap |
| T1584.005 | BotnetRD | 3 | 2 | 0 | pre |
| T1611 | Escape to HostPE | 3 | 3 | 2 | |
| T1001 | Data ObfuscationCaC | 2 | 2 | 0 | gap |
| T1018 | Remote System DiscoveryD | 2 | 2 | 17 | |
| T1021.001 | Remote Desktop ProtocolLM | 2 | 2 | 16 | |
| T1021.004 | SSHLM | 2 | 2 | 5 | |
| T1033 | System Owner/User DiscoveryD | 2 | 2 | 30 | |
| T1036 | MasqueradingDE | 2 | 2 | 40 | |
| T1040 | Network SniffingCA/D | 2 | 2 | 9 | |
| T1047 | Windows Management InstrumentationE | 2 | 2 | 52 |
| ID | Technique | Sig | KEV | Rules | State |
|---|---|---|---|---|---|
| T1053 | Scheduled Task/JobE/P/PE | 2 | 2 | 12 | |
| T1053.005 | Scheduled TaskE/P/PE | 2 | 2 | 51 | |
| T1056.001 | KeyloggingC/CA | 2 | 1 | 3 | |
| T1059.001 | PowerShellE | 2 | 1 | 220 | |
| T1071 | Application Layer ProtocolCaC | 2 | 1 | 7 | |
| T1098 | Account ManipulationP/PE | 2 | 2 | 32 | |
| T1098.004 | SSH Authorized KeysP/PE | 2 | 1 | 0 | rule |
| T1136.001 | Local AccountP | 2 | 2 | 16 | |
| T1140 | Deobfuscate/Decode Files or InformationDE | 2 | 2 | 18 | |
| T1195.002 | Compromise Software Supply ChainIA | 2 | 2 | 17 | |
| T1213 | Data from Information RepositoriesC | 2 | 2 | 7 | |
| T1218 | System Binary Proxy ExecutionDE | 2 | 2 | 153 | |
| T1219 | Remote Access ToolsCaC | 2 | 1 | 6 | |
| T1482 | Domain Trust DiscoveryD | 2 | 2 | 17 | |
| T1490 | Inhibit System RecoveryI | 2 | 2 | 27 | |
| T1495 | Firmware CorruptionI | 2 | 2 | 1 | |
| T1499.002 | Service Exhaustion FloodI | 2 | 2 | 0 | gap |
| T1499.004 | Application or System ExploitationI | 2 | 2 | 3 | |
| T1505 | Server Software ComponentP | 2 | 2 | 1 | |
| T1530 | Data from Cloud StorageC | 2 | 2 | 0 | gap |
| T1547 | Boot or Logon Autostart ExecutionP/PE | 2 | 1 | 7 | |
| T1553.005 | Mark-of-the-Web BypassDE | 2 | 2 | 6 | |
| T1556 | Modify Authentication ProcessDE/P/CA | 2 | 2 | 12 | |
| T1560.001 | Archive via UtilityC | 2 | 2 | 17 | |
| T1565 | Data ManipulationI | 2 | 2 | 3 | |
| T1565.001 | Stored Data ManipulationI | 2 | 2 | 6 | |
| T1588.001 | MalwareRD | 2 | 2 | 1 | pre |
| T1592 | Gather Victim Host InformationR | 2 | 2 | 0 | pre |
| T1622 | Debugger EvasionDE/D | 2 | 2 | 1 | |
| T1003.008 | /etc/passwd and /etc/shadowCA | 1 | 1 | 0 | gap |
| T1007 | System Service DiscoveryD | 1 | 1 | 11 | |
| T1016 | System Network Configuration DiscoveryD | 1 | 1 | 11 | |
| T1036.005 | Match Legitimate Resource Name or LocationDE | 1 | 1 | 21 | |
| T1048.003 | Exfiltration Over Unencrypted Non-C2 ProtocolE | 1 | 1 | 9 | |
| T1049 | System Network Connections DiscoveryD | 1 | 1 | 9 | |
| T1055.001 | Dynamic-link Library InjectionDE/PE | 1 | 1 | 8 | |
| T1055.012 | Process HollowingDE/PE | 1 | 1 | 5 | |
| T1056.002 | GUI Input CaptureC/CA | 1 | 0 | 3 | |
| T1069 | Permission Groups DiscoveryD | 1 | 1 | 3 | |
| T1071.002 | File Transfer ProtocolsCaC | 1 | 1 | 0 | gap |
| T1078.003 | Local AccountsDE/P/PE/IA | 1 | 1 | 5 | |
| T1078.004 | Cloud AccountsDE/P/PE/IA | 1 | 1 | 40 | |
| T1087.001 | Local AccountD | 1 | 1 | 13 | |
| T1090.001 | Internal ProxyCaC | 1 | 1 | 6 | |
| T1113 | Screen CaptureC | 1 | 0 | 10 | |
| T1114.002 | Remote Email CollectionC | 1 | 1 | 0 | gap |
| T1119 | Automated CollectionC | 1 | 1 | 5 | |
| T1134.001 | Token Impersonation/TheftDE/PE | 1 | 1 | 9 | |
| T1195 | Supply Chain CompromiseIA | 1 | 1 | 1 | |
| T1199 | Trusted RelationshipIA | 1 | 1 | 1 | |
| T1211 | Exploitation for StealthDE | 1 | 1 | 4 | |
| T1217 | Browser Information DiscoveryD | 1 | 1 | 4 | |
| T1222 | File and Directory Permissions ModificationDE | 1 | 1 | 2 | |
| T1484.001 | Group Policy ModificationDE/PE | 1 | 1 | 6 | |
| T1489 | Service StopI | 1 | 1 | 20 | |
| T1491.002 | External DefacementI | 1 | 1 | 0 | gap |
| T1498.001 | Direct Network FloodI | 1 | 1 | 0 | gap |
| T1528 | Steal Application Access TokenCA | 1 | 1 | 14 | |
| T1531 | Account Access RemovalI | 1 | 1 | 9 | |
| T1542.005 | TFTP BootDE/P | 1 | 1 | 0 | gap |
| T1547.001 | Registry Run Keys / Startup FolderP/PE | 1 | 1 | 39 | |
| T1547.009 | Shortcut ModificationP/PE | 1 | 1 | 4 | |
| T1548.001 | Setuid and SetgidPE | 1 | 1 | 2 | |
| T1548.002 | Bypass User Account ControlPE | 1 | 1 | 56 | |
| T1552.004 | Private KeysCA | 1 | 1 | 7 | |
| T1555.001 | KeychainCA | 1 | 0 | 1 | |
| T1557.001 | Name Resolution Poisoning and SMB RelayCA/C | 1 | 1 | 10 | |
| T1569.002 | Service ExecutionE | 1 | 1 | 43 | |
| T1570 | Lateral Tool TransferLM | 1 | 1 | 6 | |
| T1571 | Non-Standard PortCaC | 1 | 1 | 5 | |
| T1588 | Obtain CapabilitiesRD | 1 | 1 | 2 | pre |
| T1588.006 | VulnerabilitiesRD | 1 | 1 | 0 | pre |
| T1595 | Active ScanningR | 1 | 1 | 3 | pre |
| T1598.002 | Spearphishing AttachmentR | 1 | 1 | 1 | pre |
| T1601 | Modify System ImageDE | 1 | 1 | 0 | gap |
| T1602 | Data from Configuration RepositoryC | 1 | 1 | 0 | gap |
| T1653 | Power SettingsP | 1 | 1 | 1 |
Signal = MISP citations + KEV CVEs mapped (CTID) + active-family presence. Coverage = SigmaHQ community rules tagged to the technique. Structural exclusion: pre-compromise tactics (Reconnaissance, Resource Development) are not writable detection gaps. Source: MITRE ATT&CK & CTID mappings · CISA KEV · CIRCL MISP · SigmaHQ · 2026-07-14.