Threat-Informed Defence

Defensive Gap Analysis

Rate your organisation's control maturity against the aggregate threat actor TTP heatmap. Instantly see where your defences are missing for the highest-priority threats.

20 actors in scope
42
Techniques in scope
42
Gaps identified
0
Planned / Partial
0
Fully covered
Priority Gaps — Most-Targeted Techniques with No Controls
T1486Impact
AP
LO
RA
AL
10 actors
T1190Initial Access
AP
AP
LO
RA
9 actors
T1078Privilege Escalation
AP
AP
AP
RA
7 actors
T1490Impact
LO
RA
AL
BL
7 actors
T1048Exfiltration
LO
AL
CL
AK
6 actors

Gap Coverage by Kill Chain Phase

Proportion of techniques with missing controls in each ATT&CK phase.

Initial Access
8/8 gaps
100%
Execution
3/3 gaps
100%
Persistence
4/4 gaps
100%
Privilege Escalation
1/1 gaps
100%
Defence Evasion
5/5 gaps
100%
Credential Access
4/4 gaps
100%
Lateral Movement
2/2 gaps
100%
Collection
5/5 gaps
100%
Exfiltration
5/5 gaps
100%
Impact
5/5 gaps
100%

Technique-Level Gap Breakdown

Rate each control. Expand a technique to toggle maturity for its individual defensive controls.

Control Maturity Register

Rate all unique defensive controls in one place. Changes save automatically.

0 of 118 controls implemented0% coverage
Essential

Rapid patch cadence (48-hr SLA for critical CVEs)

Essential

Email sandboxing & attachment detonation

Essential

Disable Office macros via Group Policy

Essential

Email sandboxing & link rewriting

Essential

File integrity monitoring (FIM) on web roots

Essential

Application whitelisting / WDAC

Essential

EDR with behavioural analytics

Essential

Phishing-resistant MFA (FIDO2)

Essential

Least-privilege access model

Essential

MFA enforcement on all cloud services

Essential

Immutable, off-device SIEM logging

Essential

Alert on log gap / tampering events

Essential

Encrypted communications (TLS 1.3 / E2E)

Essential

Management plane isolation (OOB)

Essential

New account creation alerting

Essential

VPN appliance patching (critical priority)

Essential

MFA on all remote access (FIDO2)

Essential

EDR with memory protection (Credential Guard)

Essential

Network segmentation to limit blast radius

Essential

Immutable backups (WORM / offline copy)

Essential

EDR with ransomware behavioural detection

Essential

Backup isolation (air-gap or WORM)

Essential

PowerShell constrained language mode

Essential

EDR with PowerShell behavioural detection

Essential

Phishing-resistant MFA (FIDO2 / passkeys)

Essential

Phishing-resistant MFA (session cookie resistant)

Essential

Device registration approval workflow in IdP

Essential

Least-privilege access to sensitive repos

Essential

Incident response retainer (pre-contracted)

Essential

Notifiable Data Breach response plan

Essential

Cloud storage access policy & CSPM

Essential

Immutable backups (WORM / offline)

Essential

EDR with process injection detection

Essential

RDP access restricted to PAWs / jump servers

Essential

MFA on all RDP sessions

Essential

EDR tamper protection enabled

Essential

Alerting on security tool process termination

Essential

EDR behavioural analytics

Essential

Least-privilege user model on Linux

Core

Web application firewall (WAF)

Core

Security awareness training

Core

DNS-layer filtering

Core

Web server hardening

Core

Outbound HTTPS inspection

Core

Script block logging

Core

Privileged access workstations (PAWs)

Core

Conditional access with device compliance

Core

Background screening & access reviews

Core

Cloud credential scanning

Core

Cloud CSPM

Core

Egress proxy with TLS inspection

Core

DLP on endpoint and email egress

Core

Data classification & sensitivity tagging

Core

Tamper-evident audit trail

Core

Vendor security assessment (TPRM)

Core

Secure SDLC

Core

Third-party update integrity verification

Core

Certificate pinning

Core

Network-level encryption (mTLS)

Core

Privileged identity management (PIM)

Core

Anomalous account change detection

Core

VPN traffic behavioural analytics

Core

LSASS protection via Windows Credential Guard

Core

Behavioural network baseline (not geo-IP)

Core

DNS over HTTPS (DoH) inspection

Core

DDoS protection (cloud-based scrubbing)

Core

Network segmentation to limit propagation

Core

Egress proxy with DLP inspection

Core

SIEM alerting on anomalous outbound data volume

Core

VSS protection via GPO / tamper alerts

Core

EDR alerting on vssadmin execution

Core

Service creation monitoring in SIEM

Core

Least-privilege service account model

Core

Script block logging & AMSI integration

Core

MFA push notification rate limiting

Core

Help desk social engineering training

Core

Zero trust email controls

Core

Anomalous internal email pattern detection

Core

AiTM phishing detection (Entra ID Protection)

Core

Alert on new device registration from unmanaged device

Core

DLP on SharePoint / Confluence / repos

Core

CASB — block bulk uploads to non-approved storage

Core

DLP on cloud egress

Core

Cyber insurance with extortion coverage

Core

CASB with cloud anomaly detection

Core

API rate limiting & DLP on API egress

Core

Change management controls on critical data

Core

EDR alerting on mass file modification

Core

SIEM alerting on automated bulk transfers

Core

DLP on automated egress channels

Core

Memory integrity protection

Core

PAM session recording for privileged RDP

Core

Privileged access required to modify security config

Core

Command shell execution monitoring in SIEM

Core

Linux EDR / auditd rules for shell execution

Core

Container / VM security hardening

Core

CASB — cloud storage upload monitoring

Core

DLP on egress to unapproved cloud services

Core

Email filtering (typosquat domain detection)

Enhanced

External attack surface management (EASM)

Enhanced

Browser isolation

Enhanced

Insider threat program

Enhanced

CASB for cloud service anomaly detection

Enhanced

JA3/JA4 TLS fingerprinting in SIEM

Enhanced

UEBA — anomalous bulk access alerts

Enhanced

Software supply chain security (SBOM)

Enhanced

Code signing & build integrity

Enhanced

CALEA architecture security review

Enhanced

Network device integrity verification

Enhanced

Zero trust network architecture

Enhanced

Resilience testing & continuity plans

Enhanced

Data classification & tagging

Enhanced

Insider threat monitoring program

Enhanced

Browser isolation for privileged users

Enhanced

UEBA — anomalous data repository access

Enhanced

Egress traffic anomaly alerting in SIEM

Enhanced

Network flow monitoring (NetFlow / IPFIX)

Enhanced

Proxy with category-based blocking

Turn gaps into a roadmap

Commission a prioritised remediation assessment

Our analysts will validate your control maturity against live threat actor TTPs and build a risk-ranked remediation roadmap.

Feisty Fox LogoFeisty Fox Security

© 2026 Feisty Fox Security. All rights reserved.