The assessment
Ten screens in the tool, covering six methodological stages: derive your in-scope technique set from your environment, your adversaries and your attack paths, compute what your telemetry cannot see, score the capability, and produce a ranked plan.
Ten screens, six stages — why the two numbers differ. The stages below are the method. The tool splits one of them, threat scope, across four screens — crown jewels, threat actors, likely attacks and attack paths — because each needs its own decision and its own list, and asking for all four at once is how scoping gets skipped. Nothing is added or removed by the split; it is the same six stages, paced.
It runs entirely in your browser. No account, no email address, no server, no analytics, no network requests. Your assessment is saved to your own browser storage and never leaves the page — which is also why there is no endpoint that scores an assessment for you.
Start the assessment Read the guide first
The six stages
Environment
What you run, what you collect and how you work. Everything downstream is derived from this.
Threat scope
Crown jewels, threat actors, the techniques most likely to be used against you, and the attack paths that make a technique matter.
Telemetry
How much of your estate each log source actually covers, and what that makes structurally undetectable.
Capability
Scoring the sub-capabilities in your profile, with the evidence that substantiates each claim.
Results
The adjusted score, which constraints bound it, and which adversaries would walk through the gaps.
Roadmap
What to fix, ranked by what it unlocks, and a 30/60/90 plan naming owners and the artefact that proves each step is done.