Would you actually see the adversaries
most likely to attack you?

Most organisations cannot answer that. They can tell you how many rules they run and how many alerts they close — neither of which measures capability. TID-CMM measures whether your detection is driven by adversary behaviour, and whether it has been proven to work.

Version 1.1.0 · 8 domains · 58 sub-capabilities · aligned to MITRE ATT&CK Enterprise v19.2 (697 techniques) · crosswalked to NIST CSF 2.0, SOC-CMM and ISO/IEC 27001:2022 · open licence, nothing to buy, nothing to install.

The problem

A rule that has never fired on a true positive, running on a log source that stopped reporting six weeks ago, mapped to a technique your adversaries do not use, counts exactly the same as a detection proven to catch a real intrusion in minutes. Every standard metric treats them identically.

Coverage claimed without visibility

A rule exists, is enabled, is mapped to a technique — and cannot fire, because the data source is deployed on 60% of the estate or stopped parsing after an agent upgrade. Nothing tests it. Nothing monitors it.

Detection built without a threat model

Enable a content subscription and matrix coverage rises impressively. But the adversary who matters doesn't need a technique the content covers — they need the path through your estate that nobody modelled.

Capability asserted without evidence

"Would we detect credential dumping?" "There's a rule for it, so yes." That answer then reaches a risk register, a board pack and a budget decision. It is tested for the first time by an adversary.

Detection is bounded by visibility, and now that is measurable

MITRE ATT&CK v19 replaced its old data-source model with detection strategies and analytics that reference concrete log sources and channels. That turns a caveat into a computation.

423 techniques — 89% of all Windows techniques in ATT&CK Enterprise v19.2 — have detection analytics that reference Sysmon. For 20 of them, Sysmon is the only log source referenced. If you do not run it or an EDR supplying equivalent process, command line and module telemetry, that is not a gap in your rule set. It is a gap in physics.

TID-CMM computes this for the techniques you scoped as relevant, bands each one as assured, partial, weak or blind against how much of your estate each source actually covers, and ranks what to enable by how many in-scope techniques it unblocks — naming capabilities and free routes, never products.

Check your telemetry assurance →

What makes this different

Three deliberate design decisions, and they are the whole point.

1

Validation is a domain, not a footnote

Atomic testing, breach and attack simulation, threat-actor emulation, purple teaming, penetration testing and red teaming are scored together as the evidence engine of the model.

2

Threat modeling and attack paths are a domain

Attack trees with every node mapped to ATT&CK and every leaf carrying a prevent/detect/accept decision. Computed attack paths through identity and cloud entitlement. Traceability from a modelled node to a deployed detection.

3

The assessment cannot flatter itself

Four integrity constraints are applied mechanically at scoring time. Exhortation to "be honest" does not survive a budget cycle. Arithmetic does.

The four integrity constraints

IDConstraintRule
C1Validation ceiling No domain may exceed the validation domain score + 1. An untested capability is an assumed capability.
C2Visibility ceiling Detection engineering may not exceed telemetry coverage + 1. Detection logic cannot outrun its data.
C3Evidence rule A score of 4 or 5 with no named artefact is counted as 3.
C4Intent ceiling Telemetry and detection may not exceed threat intelligence and threat modeling + 1. Sensors without architectural intent produce noise, not defence.
In the worked example, an organisation with genuinely strong security operations self-assesses at 2.44 and scores 2.34 after constraints — because four separate domains were capped by a validation score of 1.63. The model does not merely report a lower number. It identifies the single investment that would raise every other domain.

The eight domains

Each scored 0–5 against explicit descriptors, weighted, and rolled up. Weights are exposed as editable parameters in every tool, because they are a judgement and you should be able to argue with them.

IDDomainWeight Sub-capsThe question it answers
TIThreat Intelligence & Adversary Prioritisation12.0%6Who are we defending against, and how do we know?
TMThreat Modeling & Attack Path Analysis12.0%7What do their behaviours look like against our architecture?
DCTelemetry & Detection Coverage14.0%6Can we see the activity at all?
DEDetection Engineering16.0%10Do we build, test and maintain detection like engineers?
AVAdversarial Validation & Emulation14.0%8Have we proven any of it works?
AAAnalytics, Automation & Hunting12.0%8Does detection output become a decision at operational tempo?
IRIncident Response & Recovery10.0%6Can we act on what we detect?
GVGovernance, Metrics & Continuous Improvement10.0%7Is this directed, measured and sustainable?

Honest coverage, not a green matrix

TID-CMM replaces "% of ATT&CK covered" with the Validated Coverage Score, computed only over the techniques you have scoped as genuinely relevant to your platforms and threat profile.

StatusMeaning
0No telemetry — you are blind
1Telemetry only — queryable, nothing alerts
2Detection logic exists — deployed and healthy, but unproven
3Validated by emulation — proven to fire, within the recency window

Status 3 expires. A detection proven eighteen months ago, across two platform migrations and a schema change, is not proven now.

Why it matters

In the worked example the organisation would report 48.9% ATT&CK coverage — a respectable figure that would pass unchallenged in most board packs.

The proportion it has actually proven is 12.7%.

The gap between those two numbers is the entire argument for this model.

48.9%
Has detection logic
12.7%
Actually proven

What you get

Open licence. No account, no email address, no sales call.

The assessment tool

Seven guided steps that follow the model's own logic: what you run, what you protect, who targets you, how they would reach it, what you can see, how you work, where you stand.

It derives your in-scope ATT&CK set from your environment, your threat actors and your attack paths — typically 200 techniques rather than 697 — then tells you which of them you are structurally unable to detect with the telemetry you have, and exactly what to enable.

Runs entirely in your browser. No server, no analytics, no network requests.

Start the assessment →

Everything else

  • White paper — 59 pages: rationale, positioning against SOC-CMM, DEBMM, CTEM and NIST CSF 2.0, the full model, method and worked example.
  • Excel workbook — 15 tabs, live formulas, radar chart, all 697 ATT&CK techniques, ranked roadmap.
  • Worked example — a completed assessment, pre-filled.
  • Machine-readable model — YAML, JSON Schema, Python scoring engine.
  • ATT&CK dataset — normalised, with required data components per technique.
All downloads →

How it fits what you already run

TID-CMM is designed to sit alongside your existing frameworks, not replace them.

FrameworkRelationship
MITRE ATT&CKConsumed. Every coverage claim is anchored to technique and sub-technique IDs at v19.2.
SOC-CMMComplementary. SOC-CMM assesses the SOC as an operating unit; TID-CMM asks whether it would see the adversary. Crosswalked per sub-capability.
NIST CSF 2.0Reporting layer. Every sub-capability maps to CSF outcomes, so an assessment feeds existing reporting without a second exercise.
Elastic DEBMMOverlapping and compatible. DEBMM goes deeper on detection engineering; TID-CMM covers the whole loop.
Gartner CTEMComplementary. CTEM asks whether an exposure can be exploited; TID-CMM asks whether the exploitation would be seen.
ISO/IEC 27001:2022Control-existence oriented. TID-CMM is the evidence layer underneath.

Start here

Half a day

Run a rapid self-assessment to get a baseline and see which conversations you need to have. Don't report the number yet.

Open the tool

Two weeks

Run a structured assessment with evidence and the right people in the room. Read the guide first — the participation set and the scoping step both matter more than the scoring.

Read the guide

Contribute

The model is open and versioned. Descriptors, weights and crosswalks are all open to challenge. If a level descriptor doesn't match what you see in practice, say so with the counter-example.

GitHub

Common questions

What is a threat-informed detection capability maturity model?

A threat-informed detection capability maturity model measures whether an organisation's threat detection is driven by the behaviour of the adversaries most likely to attack it, and whether that detection has been proven to work. TID-CMM scores eight domains and 58 sub-capabilities from 0 to 5, anchored to MITRE ATT&CK Enterprise v19.2.

Is 100% MITRE ATT&CK coverage a realistic goal?

No. ATT&CK is a catalogue of behaviour observed across all sectors and platforms, not a requirements list. Of its 697 techniques, 475 are sub-techniques, and the techniques are not comparable units, so summing them into a percentage is misleading. A realistic goal is deep, validated coverage of a scoped set derived from your platforms, your prioritised threat actors and your attack paths — typically 150 to 250 techniques.

How do I know whether I have the telemetry to detect a technique?

Compare the log sources each technique's ATT&CK detection analytics require against what you actually collect, weighted by how much of your estate each source covers. TID-CMM computes this automatically and reports each technique as assured, partial, weak or blind, then ranks the telemetry to enable by how many in-scope techniques it unblocks.

How much of MITRE ATT&CK depends on Sysmon?

423 techniques — 89% of all Windows techniques in ATT&CK Enterprise v19.2 — have detection analytics that reference Sysmon. For 20 of them Sysmon is the only log source referenced. Organisations without Sysmon or an EDR providing equivalent process, command line and module telemetry are structurally unable to detect those behaviours.

Is TID-CMM free?

Yes. The model is licensed CC-BY-4.0 and the tooling Apache-2.0. The assessment tool, Excel workbook, white paper and datasets are free to download and use commercially with attribution. There is no account, no certification scheme and nothing to buy.