ATT&CK is a catalogue of what attackers actually do, organised by tactic (the goal) and technique (the method). Its value is that red and blue can describe the same event in the same words.
Using it for testing
Pick techniques relevant to your environment and threat model, not all of them. A Windows-heavy enterprise and a cloud-native startup share very little of the matrix. For each chosen technique, ask: can it be performed here, is it prevented, and if not, is it detected?
Using it for detection
The honest version of coverage mapping is a three-column table: technique, what would detect it, and whether that detection has ever fired on a real test. The third column is the one that matters, and the one usually missing.
Beware colouring the matrix green by counting rules. A rule that fires on one trivial variant of a technique does not cover the technique; attackers adapt within a technique constantly.
Where it misleads
ATT&CK describes behaviour seen in the wild, so it is weighted towards what has been reported. It is not a risk model, it does not rank techniques by likelihood for you, and a high coverage score with no incident response capability is a number, not a defence.