rabobank-cdc/DeTTECT

Feature request: Detection & Visibility overlay, highlighting where Visibility > Detection

tailsec opened this issue · 0 comments

The existing overlay function for Detections and Visibility highlights where both exist for a given technique - while this is helpful in its current form, it could be built on to help identify opportunities to improve Detection coverage by highlighting techniques which have a greater visibility score than detection score.

Being able to generate this in the JSON overlay would highlight instances where we have the visibility of a particular technique, but potentially simply haven't gotten around to improving the detection coverage of that technique.

I imagine this would require the calculation of the delta between the scores, and those deltas being used as the basis for a separate overlay to highlight those gaps which can be addressed. Does this seem feasible and worthwhile?