Best Practice Report

The Forrester MITRE ATT&CK Evaluation Guide

An Objective Analysis Of Round 1 And How To Interpret The Results

November 20th, 2019
Josh Zelonis, null
Josh Zelonis
With contributors:
Joseph Blankenship , Stephanie Balaouras , Alexis Tatro , Peggy Dostie , Diane Lynch


In an industry desperate for objective efficacy testing performed with integrity, the introduction of the MITRE ATT&CK evaluation of endpoint detection and response (EDR) security products is a much-welcomed event. However, when MITRE published its results, it did so as a scientific data set, leaving security pros to interpret individual vendor performance on their own. This report is Forrester’s guide to understanding what each vendor’s MITRE ATT&CK evaluation results say about the competence of their offering’s ability to detect threats and enable response.

Want to read the full report?

Contact us to become a client

This report is available for individual purchase ($1495).

Forrester helps business and technology leaders use customer obsession to accelerate growth. That means empowering you to put the customer at the center of everything you do: your leadership strategy, and operations. Becoming a customer-obsessed organization requires change — it requires being bold. We give business and technology leaders the confidence to put bold into action, shaping and guiding how to navigate today's unprecedented change in order to succeed.