Detection coverage maps your existing detections against ATT&CK techniques — identifying which techniques you can detect (green), which are gaps (red), and prioritizing new detection development.
ATT&CK Navigator (free MITRE tool) visualizes coverage. Start by mapping existing SIEM rules and EDR detections. Prioritize coverage based on your threat intelligence — focus on techniques used by groups targeting your industry. Use purple team exercises to validate coverage is actually working.