Overview
Read Security Posture Score and coverage from Detections → Overview.
The Overview tab summarizes the metrics and action items from all validation data.
Open Overview
- Go to Detections → Overview.
Security Posture Score

The centerpiece of the Overview tab is the Security Posture Score, a single 0-100 metric displayed as a circular progress indicator. The score is color-coded by rating and computed from three weighted components:
Formula: (Attack Coverage x 0.4) + (Defense Coverage x 0.35) + (Effective Defense x 0.25)
The resulting score maps to a five-tier rating:
If no validation data has been collected yet, the ring shows — and the badge reads Not Assessed. The note under it says the score will reflect ATT&CK coverage, D3FEND deployment, and control effectiveness once validation is performed. While a session is active and no results have arrived, the badge reads Monitoring active — awaiting results.
Coverage Breakdown
Beside the score widget, a horizontal bar chart compares three metrics. The bars are labeled ATT&CK, D3FEND, and Effective.
Top Security Gaps
A table lists the highest-priority security gaps ranked by criticality, showing:
- Technique - The ATT&CK technique ID and name
- Tactic - The ATT&CK tactic category the technique belongs to
- Missing Defenses - The count of D3FEND controls that are not effectively deployed for this technique
- Risk Score - A 0-100 score factoring in prevalence weight, defense status, and test outcome
- Priority - Critical, High, Medium, or Low
Clicking any row navigates directly to that technique in the Gap Analysis tab. A footer summarizes gap counts by tactic.
Recommended Actions
The Recommendations widget analyzes all current gaps and identifies which D3FEND techniques would provide the greatest coverage improvement if deployed. Recommendations are ranked by impact — the number of undefended ATT&CK techniques each D3FEND control would help cover. Each recommendation links to the official D3FEND documentation for the suggested technique.
MITRE ATT&CK, D3FEND, and EMB3D heatmaps are on Insights → Benchmarks, not on this page.
How Data Feeds Into Detections
Validation data comes from two primary sources:
- BAS Monitoring Sessions — A session polls connected Microsoft Defender, SentinelOne, and ExtraHop integrations for alerts that match its filters and selected ATT&CK techniques.
- MITRE Framework Reference Data — Guard maintains curated ATT&CK, D3FEND, and EMB3D datasets, along with technique-to-control mappings and prevalence weights derived from industry research. These datasets provide the structural backbone that validation results are scored and visualized against.
All scores, gap analyses, and recommendations are computed from the combination of these two sources — real test outcomes mapped against the full MITRE framework landscape.
More in Detections
DecoysNuclei Template Validation PipelineDetectionsGap AnalysisStill need help? Ask the team