Quantify Zscaler MDR’s Threat Coverage Using MITRE ATT&CK

Prev Next

Building a great security operations program depends on layering the right detection techniques and security products to cover the appropriate number of adversary techniques for your business. This has historically been very difficult because most security products take a black box approach that does not transparently explain what techniques are covered.

We strive to make Zscaler MDR’s coverage of adversary techniques transparent and understandable so you can ensure that your program is investing in the right security solutions.

Zscaler MDR detection analytics are mapped to the MITRE ATT&CK® framework to ensure consistent language around adversary techniques. All behavioral detection analytics are mapped to one or more associated MITRE ATT&CK techniques.

View a MITRE ATT&CK matrix of Zscaler MDR detector coverage for adversary techniques

You can view a MITRE ATT&CK matrix in the Zscaler MDR portal that highlights which techniques are associated with one or more detection analytics. All techniques with one or more associated Zscaler MDR detection analytics are shaded green to indicate a level of coverage.

  1. In the Zscaler MDR portal, click Analytics, then Attack Techniques to see a matrix of all adversary techniques.

  2. Click Export Navigator Layers, and then select Techniques covered by Zscaler MDR detectors.

  3. A Navigator layer file will be downloaded; import this file into your MITRE ATT&CK Navigator.