Most organisations cannot answer that. They can tell you how many rules they run and how many alerts they close — neither of which measures capability. TID-CMM measures whether your detection is driven by adversary behaviour, and whether it has been proven to work.
A rule that has never fired on a true positive, running on a log source that stopped reporting six weeks ago, mapped to a technique your adversaries do not use, counts exactly the same as a detection proven to catch a real intrusion in minutes. Every standard metric treats them identically.
A rule exists, is enabled, is mapped to a technique — and cannot fire, because the data source is deployed on 60% of the estate or stopped parsing after an agent upgrade. Nothing tests it. Nothing monitors it.
Enable a content subscription and matrix coverage rises impressively. But the adversary who matters doesn't need a technique the content covers — they need the path through your estate that nobody modelled.
"Would we detect credential dumping?" "There's a rule for it, so yes." That answer then reaches a risk register, a board pack and a budget decision. It is tested for the first time by an adversary.
MITRE ATT&CK v19 replaced its old data-source model with detection strategies and analytics that reference concrete log sources and channels. That turns a caveat into a computation.
423 techniques — 89% of all Windows techniques in ATT&CK Enterprise v19.2 — have detection analytics that reference Sysmon. For 20 of them, Sysmon is the only log source referenced. If you do not run it or an EDR supplying equivalent process, command line and module telemetry, that is not a gap in your rule set. It is a gap in physics.
TID-CMM computes this for the techniques you scoped as relevant, bands each one as assured, partial, weak or blind against how much of your estate each source actually covers, and ranks what to enable by how many in-scope techniques it unblocks — naming capabilities and free routes, never products.
Three deliberate design decisions, and they are the whole point.
Atomic testing, breach and attack simulation, threat-actor emulation, purple teaming, penetration testing and red teaming are scored together as the evidence engine of the model.
Attack trees with every node mapped to ATT&CK and every leaf carrying a prevent/detect/accept decision. Computed attack paths through identity and cloud entitlement. Traceability from a modelled node to a deployed detection.
Four integrity constraints are applied mechanically at scoring time. Exhortation to "be honest" does not survive a budget cycle. Arithmetic does.
| ID | Constraint | Rule |
|---|---|---|
| C1 | Validation ceiling | No domain may exceed the validation domain score + 1. An untested capability is an assumed capability. |
| C2 | Visibility ceiling | Detection engineering may not exceed telemetry coverage + 1. Detection logic cannot outrun its data. |
| C3 | Evidence rule | A score of 4 or 5 with no named artefact is counted as 3. |
| C4 | Intent ceiling | Telemetry and detection may not exceed threat intelligence and threat modeling + 1. Sensors without architectural intent produce noise, not defence. |
In the worked example, an organisation with genuinely strong security operations self-assesses at 2.44 and scores 2.34 after constraints — because four separate domains were capped by a validation score of 1.63. The model does not merely report a lower number. It identifies the single investment that would raise every other domain.
Each scored 0–5 against explicit descriptors, weighted, and rolled up. Weights are exposed as editable parameters in every tool, because they are a judgement and you should be able to argue with them.
| ID | Domain | Weight | Sub-caps | The question it answers |
|---|---|---|---|---|
| TI | Threat Intelligence & Adversary Prioritisation | 12.0% | 6 | Who are we defending against, and how do we know? |
| TM | Threat Modeling & Attack Path Analysis | 12.0% | 7 | What do their behaviours look like against our architecture? |
| DC | Telemetry & Detection Coverage | 14.0% | 6 | Can we see the activity at all? |
| DE | Detection Engineering | 16.0% | 10 | Do we build, test and maintain detection like engineers? |
| AV | Adversarial Validation & Emulation | 14.0% | 8 | Have we proven any of it works? |
| AA | Analytics, Automation & Hunting | 12.0% | 8 | Does detection output become a decision at operational tempo? |
| IR | Incident Response & Recovery | 10.0% | 6 | Can we act on what we detect? |
| GV | Governance, Metrics & Continuous Improvement | 10.0% | 7 | Is this directed, measured and sustainable? |
TID-CMM replaces "% of ATT&CK covered" with the Validated Coverage Score, computed only over the techniques you have scoped as genuinely relevant to your platforms and threat profile.
| Status | Meaning |
|---|---|
| 0 | No telemetry — you are blind |
| 1 | Telemetry only — queryable, nothing alerts |
| 2 | Detection logic exists — deployed and healthy, but unproven |
| 3 | Validated by emulation — proven to fire, within the recency window |
Status 3 expires. A detection proven eighteen months ago, across two platform migrations and a schema change, is not proven now.
In the worked example the organisation would report 48.9% ATT&CK coverage — a respectable figure that would pass unchallenged in most board packs.
The proportion it has actually proven is 12.7%.
The gap between those two numbers is the entire argument for this model.
Open licence. No account, no email address, no sales call.
Seven guided steps that follow the model's own logic: what you run, what you protect, who targets you, how they would reach it, what you can see, how you work, where you stand.
It derives your in-scope ATT&CK set from your environment, your threat actors and your attack paths — typically 200 techniques rather than 697 — then tells you which of them you are structurally unable to detect with the telemetry you have, and exactly what to enable.
Runs entirely in your browser. No server, no analytics, no network requests.
Start the assessment →TID-CMM is designed to sit alongside your existing frameworks, not replace them.
| Framework | Relationship |
|---|---|
| MITRE ATT&CK | Consumed. Every coverage claim is anchored to technique and sub-technique IDs at v19.2. |
| SOC-CMM | Complementary. SOC-CMM assesses the SOC as an operating unit; TID-CMM asks whether it would see the adversary. Crosswalked per sub-capability. |
| NIST CSF 2.0 | Reporting layer. Every sub-capability maps to CSF outcomes, so an assessment feeds existing reporting without a second exercise. |
| Elastic DEBMM | Overlapping and compatible. DEBMM goes deeper on detection engineering; TID-CMM covers the whole loop. |
| Gartner CTEM | Complementary. CTEM asks whether an exposure can be exploited; TID-CMM asks whether the exploitation would be seen. |
| ISO/IEC 27001:2022 | Control-existence oriented. TID-CMM is the evidence layer underneath. |
Run a rapid self-assessment to get a baseline and see which conversations you need to have. Don't report the number yet.
Open the toolRun a structured assessment with evidence and the right people in the room. Read the guide first — the participation set and the scoping step both matter more than the scoring.
Read the guideThe model is open and versioned. Descriptors, weights and crosswalks are all open to challenge. If a level descriptor doesn't match what you see in practice, say so with the counter-example.
GitHubA threat-informed detection capability maturity model measures whether an organisation's threat detection is driven by the behaviour of the adversaries most likely to attack it, and whether that detection has been proven to work. TID-CMM scores eight domains and 58 sub-capabilities from 0 to 5, anchored to MITRE ATT&CK Enterprise v19.2.
No. ATT&CK is a catalogue of behaviour observed across all sectors and platforms, not a requirements list. Of its 697 techniques, 475 are sub-techniques, and the techniques are not comparable units, so summing them into a percentage is misleading. A realistic goal is deep, validated coverage of a scoped set derived from your platforms, your prioritised threat actors and your attack paths — typically 150 to 250 techniques.
Compare the log sources each technique's ATT&CK detection analytics require against what you actually collect, weighted by how much of your estate each source covers. TID-CMM computes this automatically and reports each technique as assured, partial, weak or blind, then ranks the telemetry to enable by how many in-scope techniques it unblocks.
423 techniques — 89% of all Windows techniques in ATT&CK Enterprise v19.2 — have detection analytics that reference Sysmon. For 20 of them Sysmon is the only log source referenced. Organisations without Sysmon or an EDR providing equivalent process, command line and module telemetry are structurally unable to detect those behaviours.
Yes. The model is licensed CC-BY-4.0 and the tooling Apache-2.0. The assessment tool, Excel workbook, white paper and datasets are free to download and use commercially with attribution. There is no account, no certification scheme and nothing to buy.