Working on some additions to my
@MITREattack
Datamap tool, one of which is a rating for applicability in Alerting, Hunting or Forensics. The screenshot shows my rating in terms of coverage potential per technique, darker is higher true positive potential.