Built for security teams across
The challenge

You have hundreds of SIEM rules and sensors. Nobody can say what they cover.

Five questions land on every security leader's desk. Answering any of them properly takes weeks of manual cross-referencing. DEX turns each one into an answer.

01
Question

What do our detections actually cover?

You can count your SIEM rules and list your sensors, but neither tells you which attacker techniques they actually detect.

DEX

Every rule mapped to ATT&CK

An LLM reads the rule export, infers the data sources and use case behind each rule, and maps it to techniques and sub-techniques.

02
Question

Can we detect the APT groups known to target us?

Answering takes an analyst several days of cross-referencing rules against a threat report.

DEX

Scored against real adversaries

Coverage is measured against the groups observed in your industry and region, with last-observed dates for each one.

03
Question

Which rules are duplicated or dead?

Rule libraries grow through migrations and staff changes. Few teams have audited theirs.

DEX

The rule library, audited

Duplicates, dead rules and anything that can't be confidently mapped are listed individually, each with the reason.

04
Question

Are our security tools covering what they claim?

Vendor coverage matrices are self-attested, and there is no way to verify them from inside your SOC.

DEX

Vendor claims, verified

SIEM rules and vendor sensors are scored on separate axes rather than averaged, showing which techniques depend entirely on a vendor.

05
Question

What should the team build next?

Without a coverage baseline, the backlog is driven by the most recent incident.

DEX

The work, prioritised

Gaps are sorted by what they cost to close and how much each one unlocks, starting with work that needs no new spend.

All in one platform

Every answer comes out of a single run: auditable, repeatable, and ready for a board review. Re-run any time and export a shareable report.

What you can now do

Six answers you couldn't give last quarter.

Not a feature list. These are the things a security leader can state, and defend, once an assessment has run.

State coverage in technique terms.

A rule count and a sensor inventory say how much you own. Coverage says how much you detect.

Answer an advisory the same day.

Establishing whether you detect a given APT group stops being several days of manual cross-referencing.

See where you rest on one route.

Rules and sensors are scored separately, so single-route techniques surface instead of hiding inside a healthy blended number.

Find coverage you already paid for.

Most gaps close by writing rules against telemetry already flowing in, with no procurement and no new tooling.

Defend the roadmap.

The backlog is ordered by coverage unlocked against effort, so next quarter runs on evidence rather than the last incident.

Show movement over time.

Because assessments repeat, a later run measures progress against the plan the earlier one produced.

What changes

You'll know it worked when the team works differently.

Coverage percentages are the output. These four changes in how the team operates are the point.

01

Planning starts from a baseline

Quarterly detection planning opens with a coverage figure and a ranked gap list, instead of whatever the most recent incident was.

02

Engineers pull from the backlog

The next rule an engineer writes traces to a gap the assessment found, and to the coverage it unlocks when it ships.

03

Coverage questions get answered live

Whether you detect something is settled in the meeting where it's asked, with evidence rather than an estimate.

04

Progress is measured, not asserted

What changed since last quarter has an answer, because the previous assessment's target state is what this one is scored against.

By the numbers

What every assessment gives you

ATT&CK

Every Enterprise tactic and sub-technique scored

Dual-route

SIEM rules and vendor sensors measured separately

On demand

Re-run whenever you want and measure the movement

Inside DEX

Everything you need, in one console.

Coverage, adversary readiness, gaps and plan. Pick a view.

Coverage

Your whole estate, scored

ATT&CK coverage broken down by tactic, domain and detection route, so strong endpoint coverage can't mask a weak identity picture.

  • Coverage by tactic and sub-technique
  • Split across Application, Cloud, Email, Endpoint, Identity, Network
  • Rule route and sensor route side by side
dex.positka.com/coverage
Either-route
47%
headline
Rules route
18%
auditable
Sensor route
39%
vendor
Rules route by domain TODAY → UPLIFT

Navigator

The matrix, filled in

Every technique and sub-technique in the Enterprise matrix, shaded by how well your estate covers it and by which route that coverage arrives.

  • Full Enterprise matrix, scored technique by technique
  • Filter by tactic, domain or detection route
  • Drill into a cell to see the rules behind the score
dex.positka.com/navigator
Enterprise matrix BY TECHNIQUE
Detection resilient SIEM rule Sensor only Blind
Resilient
36
rule + sensor
Sensor only
89
single route
Blind
170
no route

APT readiness

Scored against the groups that target you

Readiness is measured against adversaries actually observed in your industry and region, each with the date last seen. Not a generic top-ten list.

  • Threat model scoped to your sector and country
  • Rules, sensor and detection resilience per group
  • Answer an advisory in minutes instead of days
dex.positka.com/readiness
Groups matched to your sector RESILIENCE · TODAY → UPLIFT
Lazarus Group152 techniques · last seen Apr 2026
12% → 94%
EXPOSED
Kimsuky109 techniques · last seen May 2026
15% → 94%
EXPOSED
APT29136 techniques · last seen Apr 2026
17% → 94%
WEAK
LockBit80 techniques · last seen Jul 2026
26% → 93%
WEAK
Royal53 techniques · last seen Jul 2026
36% → 92%
PARTIAL
Scenario coverage SIEM ROUTE

Backlog

A ranked plan, not a wish list

Gaps sorted by what they cost to close and how much each one unlocks, starting with work that needs no new spend or tooling.

  • Ranked by effort against coverage unlocked
  • No-new-spend items surfaced first
  • A target-state model later assessments measure against
dex.positka.com/backlog
Group 1 · write rules NO NEW INGESTION
Sysmon226 techniques
NO SPEND
Linux auditd185 techniques
NO SPEND
Windows Security Log153 techniques
NO SPEND
AWS CloudTrail51 techniques
NO SPEND
Groups 2 & 3 SETUP / PROCUREMENT
Switch on, then ruleconfig change
GROUP 2
Sensor recommendations31 net uplift
GROUP 3
Either-route
47%
today
Target state
100%
rules route
Rule gap
276
techniques
How the method holds up

A coverage number is only worth what its method is worth.

The hard parts of building this were mostly about refusing to flatter the result. Here's what that means in practice.

Nothing leaves the denominator

Rules that can't be confidently mapped are listed individually with the reason. A percentage over a quietly shrunk denominator is worse than none.

The matrix version is pinned

ATT&CK changes between releases, so the version is fixed and stated on every report. Otherwise this quarter can't be compared with the last.

Routes are never averaged

Rules and sensors are scored on separate axes. Averaging them produces a comfortable number that hides the fragility worth knowing about.

Sensor advice stays capability-first

Recommendations describe the capability a gap needs, with vendor-neutral alternatives alongside any extension of what you already own.

Your rule content stays yours

You run the extraction query in your own console and see exactly what leaves. Your rule content never trains an external model.

In their words

"Manual mapping is prone to error and exaggerated human judgement. DEX's deterministic approach maps rules accurately and gives an accurate coverage assessment, a good starting point toward continuous security posture improvement."

Murugan

Product Manager
FAQ

Questions, answered.

No. DEX gives you the extraction query. You run it in your own console and upload the export. No agent, no connector into production, and no log data leaves your environment.

Rule content is parsed regardless of the platform it came from. Bring what you have and we'll confirm your format before you commit to anything.

Expect some. Every library has them. Each one comes back listed with the reason it couldn't be confidently placed, rather than quietly dropped from the denominator.

You still get a full assessment, with rule coverage projected from your integrated telemetry and clearly labelled as projected. It shows the ceiling your data supports.

The current Enterprise release, stated on every report so results stay comparable across assessments as the matrix evolves.

That's the intended use. Assessments are self-serve, so you can run a new one whenever you want, and the target-state model means a later assessment is measured against the plan the earlier one produced. Any assessment can be exported as a shareable report.

Detection coverage and improvement recommendations are the scope. Response times, SOC capacity, alert tuning and incident-response readiness are separate workstreams, and DEX doesn't claim to measure them.

Your Security head.

No. DEX needs metadata exported from your SIEM, not raw log data and not access to the SIEM itself, so it doesn't need the review a production connector would.

Book a demo and talk to our experts. They can get you started quickly with credits.

Book a demo

See how much your detections actually cover.

Book a working session and we'll run DEX against your stack: ATT&CK coverage, APT readiness, and the first slice of your backlog.

  • Walkthrough on your own rule export
  • Scoped to your industry and region
  • No commitment, just see if it fits

Book your demo

We'll reach out within one business day.

We respect your inbox. No spam, ever.

Enquiry Now

Positka uses cookies to provide necessary site functionality and improved experience. By using our website, you agree to our privacy policy.