Home
Elezar

Product announcements

Threat-led Detection Assessment is live

Assess your SIEM rules against the adversary behaviors that matter to your organization, with coverage findings and rule evidence you can inspect.

Oct 6, 2026Team Elezar
Detection coverage map for the higher education Threat Profile showing technique coverage and gaps

Your SIEM might have hundreds of detection rules. Which ones address the behaviors used by the threats relevant to your organization? Rule counts and MITRE ATT&CK tags alone cannot answer that question. Connecting threat intelligence to detection coverage often means manually reviewing reports, technique mappings and query logic.

Threat-led Detection Assessment is now live in Elezar Sol. It connects relevant threat intelligence to your deployed SIEM rules, assessing their logic against the adversary procedures in your Threat Profile. The findings explain potential coverage, conditional matches and gaps, with supporting rule evidence to help your team prioritize detection work.

Our goal

Help your team understand how relevant adversaries operate, identify where your rules fall short and focus detection engineering where it matters most.

How to assess your detection coverage with Elezar

Run a detection assessment in four simple steps. Elezar guides you through the process with minimal configuration, so you and your team can focus on the outcomes.

  1. Define your threat profile.
  2. Connect your SIEM.
  3. Run Detection Assessment.
  4. Review output, coverage and address gaps.

Start by defining the threats that matter to your organization.

1. Detection Assessments begin: Your threat profile

Your Threat Profile helps you identify, scope and track the threats your organization should focus on. Define that scope through:

  • Targeting context: sector, geography and target technologies.
  • Adversary context: motivations and actor attributes.
  • Specific threats: threat groups, malware and campaigns.
  • Exploited vulnerabilities.

Elezar makes creating and maintaining a profile part of everyday operations. As new reports are processed, relevant intelligence updates the profile. This reduces the work of reviewing reports, deciding which ones matter and turning their findings into useful defensive priorities.

The example below shows a Threat Profile scoped to threats targeting higher education in Australia over the last 12 months.

Threat Profile filters for higher education in Australia over the last 12 months
A demonstration Threat Profile focused on higher education in Australia over the last 12 months.

The Intelligence that makes up your profile

Once you've set your scope, Elezar automatically aggregates all your adversaries, malware, campaigns and tools relevant to your profile. Everything we collect is backed by published threat intelligence.

Threat Profile dashboard summarizing the relevant adversaries, malware, campaigns and tools
The Threat Profile dashboard brings together the intelligence relevant to your selected scope.

Elezar has the world's largest library of evidence-based MITRE ATT&CK procedures, describing the concrete ways adversaries carry out ATT&CK techniques. Your profile scopes only the relevant intelligence, organized by ATT&CK tactics, techniques and sub-techniques. These procedures become the behaviors against which Sol assesses your deployed SIEM rules.

Threat library showing evidence-based adversary procedures mapped to MITRE ATT&CK
Evidence-based adversary procedures provide the intelligence against which your deployed SIEM rules are assessed.

2. Connect your SIEM

Connect your SIEM so Elezar can assess your deployed detection rules and their configuration logic. Detection Assessment currently supports Microsoft Sentinel and Rapid7 InsightIDR. Configure the integration and select the target environment you want to assess.

SIEM integration configuration in Elezar
a. Connect your SIEM integration.
Run target configuration for a Detection Assessment
b. Set the target environment for your assessment.

3. Run Detection Assessment

Open Detection within your Threat Profile and select “Assess coverage.” Choose your connected SIEM and assessment target, then run the assessment. Sol compares your rule logic against the adversary procedures relevant to your profile and returns a coverage map with supporting evidence.

Assessments run on demand. Run a fresh assessment when your threat intelligence or detection rules change to review your updated coverage.

Run a Detection Assessment in Elezar
Run a Detection Assessment against your connected SIEM and selected target.

4. Review output, coverage and address gaps

The Detection Overview brings together the adversary TTPs relevant to your Threat Profile and maps how well your deployed SIEM rule logic covers them across MITRE ATT&CK techniques. It shows where coverage is strong, conditional or missing. Open a technique to explore the procedures and rule evidence behind its grade.

Sol examines the query logic, including conditions, filters, exclusions, joins and thresholds. Disabled or untagged rules do not contribute, so missing rule metadata can also explain an apparent gap.

Detection coverage map for the higher education Threat Profile showing technique coverage and gaps

The grades below help detection engineers and SOC teams prioritize improvements and estimate the effort required to close gaps, so their rules address the relevant threat behaviors.

GradeMeaning for a group of related procedures
HighAll assessed behaviors have direct coverage.
MediumSome assessed behaviors have direct coverage, but not all.
LowNo assessed behavior has direct coverage, but at least one has conditional coverage.
NoneNo assessed behavior is covered by the matching rules.
UnknownThe behavior cannot be meaningfully assessed as an observable SIEM detection target.

Behind each coverage grade, Sol identifies how your rules match the relevant adversary procedures. Matches are classified as direct or conditional, helping you understand what supports the grade and where coverage depends on additional conditions.

  • Direct match: the rule logic addresses the assessed adversary behavior.
  • Conditional match: the rule logic addresses the behavior only when additional conditions are met. For example, a rule matching known malicious URLs may cover a command-and-control procedure only when the relevant URL is present in its indicator feed.
Conditional procedure match showing the coverage explanation and supporting SIEM rule evidence
A conditional match shows the supporting SIEM analytics and the conditions their coverage depends on.

Full visibility and transparency

Elezar Sol integrates directly with your SIEM, giving it visibility into your detection rules and their configuration logic. Sol compares that logic against relevant adversary behaviors grounded in published threat intelligence, explaining the evidence behind each coverage finding.

Each assessment preserves the rule evidence and reasoning, so you can inspect the conditions behind a match and return to the findings even after your rules change.

Click into a technique gap to see the relevant adversary procedures assessed against your deployed SIEM rules and the evidence behind each finding.

Expanded technique gap showing assessed adversary procedures and their coverage findings
Explore the assessed procedures to understand which behaviors your existing rules do not cover.

For a conditional match, Sol shows the existing SIEM analytic and explains which additional conditions must be met to cover the relevant behavior. You can inspect the supporting rule logic to understand what is needed to close the gap.

Conditional match detail showing an existing SIEM analytic and the conditions required for coverage
Inspect the supporting SIEM analytic and the conditions behind a conditional match.

This gives your team visibility into which MITRE ATT&CK techniques need attention, why they matter to your Threat Profile and where your rules fall short. You can trace each finding to the relevant adversary procedures and rule evidence, then prioritize the detection work needed to address it.

Create and validate detection analytics via Sol Agent

Sol Agent helps you turn an identified coverage gap into a detection rule you can test against your own telemetry.

Start by selecting “Ask Sol” within the detection gap window. This loads the assessment context into the agent. Specify the MITRE ATT&CK technique you want to cover, then ask Sol to draft and test a rule for the relevant adversary behavior.

Sol checks whether your environment has the data needed to support the rule and highlights any telemetry gaps. When the required data is available, it runs the query in your environment and returns the results, so you can review how the rule performs against your data.

Sol Agent assisting with detection rule creation and validation using assessment context
Use the assessment context to work with Sol Agent on a rule for the identified gap.

Once you are satisfied with the results, copy the rule and its desired trigger configuration into your SIEM. Run Detection Assessment again to see how the new rule improves coverage and identify any remaining gaps.

Features: Scale your detection engineering

Sol connects relevant threat intelligence to your deployed SIEM rules, helping your team prioritize gaps, inspect the evidence and develop rules to address them.

FeatureWhat it helps you do
Assess against your Threat ProfileFocus on relevant adversary procedures aligned to MITRE ATT&CK, rather than treating every technique as equally important.
Analyze SIEM rule logicUse ATT&CK mappings to select rules, then examine their conditions, filters, exclusions, joins and thresholds to assess potential coverage.
Review coverage by technique and tacticPrioritize techniques with gaps or conditional coverage, then explore the procedures behind each grade.
Inspect supporting evidenceReview the reasoning and saved rule logic behind each finding, including the conditions a match depends on.
Reassess against evolving intelligenceNew reporting updates the procedures relevant to your profile. Run a fresh assessment as intelligence or rules change, and revisit saved results.
Draft, run and test rules with SolAsk the agent to draft a rule for an identified gap, run it in your environment and test it.

How our approach compares

MITRE ATT&CK mapping is established across detection engineering and validation tools. Some also connect intelligence and business priorities to coverage. Elezar focuses on assessing the procedures relevant to your Threat Profile against existing SIEM rule logic, with evidence you can inspect.

PlatformDocumented coverage approachWhere Elezar focuses
AnvilogicUses threat profiles, business priorities, platforms, and feeds to align ATT&CK coverage and recommend detections. Threat prioritizationAssess relevant MITRE ATT&CK-aligned procedures against existing rule logic, with evidence of direct and conditional coverage.
SOC PrimeMaps rules and queries to ATT&CK through Content Audit, and analyzes log-source coverage through Data Audit. Prime Hunt documentationAssess how your rules address the MITRE ATT&CK-aligned procedures relevant to your Threat Profile.
SplunkProvides ATT&CK-aligned detection coverage and content recommendations within its detection engineering tooling. Detection StudioAssess rule logic against relevant MITRE ATT&CK-aligned procedures from an evolving intelligence base. New reporting changes the behaviors you assess, even when technique labels stay the same.
AttackIQExecutes adversary emulations to validate controls, maps outcomes to ATT&CK, and measures detection speed. Defense OptimizationAssess rule logic against intelligence describing how adversaries carry out MITRE ATT&CK-aligned techniques and procedures, before execution-based validation.

Based on the vendors' published descriptions reviewed on October 2, 2026. These are different workflow emphases, not claims that a vendor lacks other capabilities.

Only just getting started

Threat-led Detection Assessment in SIEM is our initial release. Currently we have:

  • Assess the threats that matter: connect Microsoft Sentinel or Rapid7 InsightIDR and assess your deployed rule logic against the adversary procedures relevant to your Threat Profile.
  • See your coverage and its evidence: review coverage by MITRE ATT&CK technique, identify gaps and conditional matches, and inspect the supporting reasoning and saved SIEM rule logic.
  • Address gaps with Sol Agent: use the assessment context to draft a detection rule, check the required telemetry, and run and test the query in your environment when the data is available.

Within a threat-led AI SOC, assessment helps you decide where detection work is needed. Threat hunting helps you investigate whether relevant adversary activity is already present. Both start from the threats that matter to your organization.

Our goal is to build toward autonomous detection analytic creation, telemetry assessment, and regular analytic testing. For now, we’re excited to put this first release in your hands and hear how it helps your team focus detection work where it matters most.

Elezar Threat-led Detection Assessment launch artwork with a pilot and spacecraft flying toward a nebula

What do your rules cover?

Start with your Threat Profile. Review your coverage, inspect the evidence, and focus on the gaps that matter.

Run Detection Assessment

Share this post