The assessment
Twelve screens in the tool, covering eight methodological stages: derive your in-scope technique set from your environment, your adversaries and your attack paths, compute what your telemetry cannot see, record what fires and what has been proven, assess the multi-step chains to your crown jewels, score the capability, and produce a ranked plan.
Twelve screens, eight stages — why the two numbers differ. The stages below are the method. The tool splits one of them, threat scope, across four screens — crown jewels, threat actors, likely attacks and attack paths — because each needs its own decision and its own list, and asking for all four at once is how scoping gets skipped. Nothing is added or removed by the split; it is the same eight stages, paced.
Which screens you see first depends on how much time you choose. The tool opens on a guided route — rapid, structured or evidence-based — that shows a shorter or longer path through the same twelve screens. All twelve stay one click away at any time, and the route changes only what is shown first and how much evidence is expected, never the model or its scoring. Read the guide for what each route covers.
It runs entirely in your browser. No account, no email address, no analytics in the application code. Your assessment is saved to your own browser storage, and the assessment code has no upload or submit path for it — which is also why there is no endpoint that scores an assessment for you. It leaves your browser only when you export it. What is stored, and where.
Start the assessment Read the guide first
The eight stages
Environment
What you run, what you collect and how you work. Everything downstream is derived from this.
Threat scope
Crown jewels, threat actors, the techniques most likely to be used against you, and the attack paths that make a technique matter.
Telemetry
How much of your estate each log source actually covers, and what that makes structurally undetectable.
Detection and validation
Per in-scope technique, Tier A first: what is deployed, whether its telemetry is healthy, and whether it has been proven to fire within your stated window. Unanswered stays not assessed.
Scenarios and timelines
Multi-step chains to a crown jewel, read step by step: observed, inferred or hypothesised; detected; validated; joined. Covered only under the existing Scenario Coverage Score rule.
Capability
Scoring the sub-capabilities in your profile, with the evidence that substantiates each claim.
Results
The adjusted score, which constraints bound it, and which adversaries would walk through the gaps.
Roadmap
What to fix, ranked by what it unlocks, and a 30/60/90 plan naming owners and the artefact that proves each step is done.