OSCAR Coverage Reports
The OSCAR Coverage Report maps OX detections and findings against the MITRE ATT&CK framework.
It visualizes how your organization’s security posture aligns with adversarial tactics and techniques, helping you identify which attack vectors are covered and where exposure remains.
By connecting OX findings to the ATT&CK matrix, the report enables AppSec and DevSecOps teams to track detection coverage, discover visibility gaps, and prioritize mitigation efforts across the attack lifecycle.
Each card within a column corresponds to a technique (TID) that OX can detect, prevent, or monitor.

Each technique card includes:
The technique ID and name (for example, T1071: SQL Injection)
Coverage indicators showing which OX modules detect or mitigate the technique
Color-coded icons indicating coverage status and data sources (for example, SBOM, PBOM, CI/CD)
Sub-techniques, if relevant, grouped under their main technique
Key Elements
Technique ID (Txxxx)
MITRE ATT&CK reference for the mapped technique.
Coverage Icons
Show the OX modules responsible for detecting or mitigating the technique.
Numbers in Circles
Indicate the number of findings, controls, or mapped assets.
Column Headers
Display the tactic name and the number of techniques covered (for example, 7/11).
Empty or Faded Cards
Represent techniques not currently covered by OX.
Example
In the Execution column, you might see the following:
T1071: SQL Injection – Covered through PBOM detections.
T1059: Command Execution – Detected through CI/CD log analysis.
T1047: Script Execution – Uncovered technique (faded card).
This view helps AppSec teams quickly identify which vectors are already addressed and where coverage should be expanded.
Using the Report
Go to Reports > OSCAR Coverage.
Review the coverage per tactic by scrolling horizontally across the MITRE framework.
Identify gaps by locating faded or uncovered techniques.
Click a technique card to view related detections, data sources, or mapped findings.
Export the report to share a coverage summary across your organization.
Last updated
