get_coverage_summary
Retrieve tactic-level detection counts as a compact summary to quickly orient detection coverage before deeper analysis. Optionally filter by source.
Instructions
Get tactic-level detection counts as a compact object (~200 bytes). Faster and smaller than analyze_coverage. Use for quick orientation before deeper analysis.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| source_type | No | Optional: filter by source (sigma, splunk_escu, elastic, kql) |