ZeroHour
Help Net Securitypublished ()ingested Industry News1

UltraViolet Cyber Equinox measures detection coverage against MITRE frameworks

infoToolsimportance 25
AI summary · glm-5.3

UltraViolet Cyber launches Equinox, an AI-automated platform mapping SIEM and EDR detection coverage against MITRE ATT&CK and ATLAS frameworks.

UltraViolet Cyber announced Equinox, a detection engineering platform from its TIDE team that maps existing detections and log sources against MITRE ATT&CK and MITRE ATLAS. It performs coverage analysis in under 30 minutes and recommends vendor or custom detections to fill gaps, with engineers reviewing and backtesting each recommendation. In one customer trial, mapped technique coverage rose from 59 of 222 techniques (26.6%) to 136 of 222 (61.3%) without increasing alert volume.

  • Maps detection coverage across SIEM and EDR against MITRE ATT&CK and ATLAS
  • Automated analysis in under 30 minutes with engineer-reviewed detections
  • Customer trial improved coverage from 26.6% to 61.3% of ATT&CK techniques
  • Extends coverage assessment to threats targeting AI and ML systems via ATLAS
Full article668 words · extracted from helpnetsecurity.com · click to collapse

UltraViolet Cyber has announced the launch of Equinox, its proprietary detection engineering platform, built and operated by the Threat Intelligence & Detection Engineering (TIDE) team. Equinox maximizes detection coverage across customers’ Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) tooling using AI and automation.

Security environments, telemetry and threat frameworks change constantly. Vendor detection libraries can include thousands of options, but what is relevant depends on each organization’s data, technology and risk profile, which can take weeks to manually analyze. Equinox identifies each customer’s current detections and available log sources and maps them against both MITRE ATT&CK and MITRE ATLAS frameworks.

UltraViolet provides a full map and scorecard to coverage status using MITRE ATLAS, specifically for adversarial tactics and techniques targeting AI and machine learning systems. The coverage prescriptively determines where mapped coverage exists, where gaps remain and which detections or log sources could improve it.

Equinox uses automation to perform the analysis in under 30 minutes, then recommends vendor or custom detections to be built and enabled to fill the identified gaps. UltraViolet’s TIDE engineers then review, backtest and approve every recommended detection before deployment, tuning it as needed. Customers receive framework-aligned evidence of where mapped detection coverage exists, how mapped coverage is changing and what to prioritize next to maximize coverage without increasing alert volume.

“Every SOC team has heard the question ‘are we actually covered?’ and struggle to answer it with full confidence,” said Dan Gittis, Director, TIDE Team at UltraViolet Cyber. “Equinox gives our TIDE engineers a real answer, in minutes instead of weeks, on not just which detections exist, but validates that a detection can actually fire against the data rather than assuming a mapped rule is effective. That’s the difference between a coverage dashboard and coverage you can defend in an audit.”

Independent industry research puts average enterprise detection coverage at 21% of MITRE ATT&CK techniques1, suggesting many organizations have telemetry capable of supporting far more mapped coverage than they currently have enabled. In a customer trial, a single Equinox review identified and validated a path from 59 of 222 covered techniques (26.6%) to 136 of 222 (61.3%) after implementation of the recommended detections. This represents a 34.7 percentage-point gain and a 130% increase in mapped technique coverage, achieved without an increase in SOC alert volume.

“Security leaders don’t lack detections, they lack visibility into whether the ones they have actually work against their own data,” said Atif Ghauri, Chief Operating Officer of UltraViolet Cyber. “Equinox closes that gap using the telemetry customers already have, before they spend a dollar on anything new. It’s a clear example of what we mean by practitioner-led, AI-accelerated: automation does the heavy lifting, our TIDE engineers make the calls that matter.”

Key benefits of Equinox include:

  • A quantified answer to “are we covered?”: Equinox shows security leaders where mapped detection coverage exists, where gaps remain and how coverage changes over time on a MITRE ATT&CK map built from a sector-specific threat model—critically validated against live telemetry, not just rule presence.
  • One coverage picture across every platform: Where a SIEM’s own dashboard shows only its own rules and data, Equinox maps coverage across every platform a customer runs into a single MITRE view, so gaps that fall between tools stay visible.
  • Maximum coverage from existing investments: Equinox identifies the detections a customer’s current telemetry and security stack can already support, expanding coverage before any new tool or data source is purchased.
  • Telemetry investment priorities: A log-source gap report quantifies the additional mapped detection coverage each new log source could support, giving teams a business case for telemetry investment.
  • Practitioner-led, AI-accelerated: Every recommended detection is reviewed, backtested against the customer’s own data and approved by a TIDE engineer before deployment — automation provides the speed, TIDE engineers provide the judgment.
  • AI-related detection coverage: Equinox extends the same assessment process to MITRE ATLAS, helping teams assess and close mapped detection coverage gaps and prioritize improvements for AI-targeted threats alongside MITRE ATT&CK.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/15/ultraviolet-cyber-equinox/