TID-CMM Threat-Informed Detection Capability Maturity Model
HomeAssessmentThreat scope

Steps 2 to 5 — threat scope

Crown jewels, threat actors, the techniques most likely to be used against you, and the attack paths that make a technique matter.

What these steps establish

These four steps turn a generic catalogue into your catalogue. Scope is an intersection: a technique must be possible on your platforms, used by adversaries you care about, and sit on a path to something worth taking.

Crown jewels

Name what you are protecting and what kind of asset it is — identity, data store, cloud control plane, source code, backups, endpoint fleet, email or OT. The category matters: it determines which tactics are weighted as high impact for you. Declaring domain controllers lifts credential access and lateral movement; declaring backups lifts the ransomware playbook.

Threat actors

Select the groups and campaigns that plausibly target your sector and geography, from ATT&CK's own actor data. Their combined technique set becomes your candidate pool.

This is where assessments stall. Choosing from 232 documented groups and campaigns with no starting point is the reason scoping gets skipped, and a technique set chosen by tooling rather than by threat is the failure the whole model exists to expose. So the tool offers a suggested threat profile: declare your sector and region on the previous step and it ranks the adversaries ATT&CK documents against organisations like yours, with the reason for each.

Accepting the suggestion unchanged caps TI.2 at level 2. TI.2 asks who you are defending against and how you know. If the tool answered it, you inherited the answer rather than producing it, and constraint C5 records that. The ceiling lifts the moment you engage with the list — add an adversary it missed, remove one that does not apply, or record why you accepted one. The constraint is not there to discourage using the feature; it is there so that using it without thinking cannot look identical to doing the analysis.

What the suggestion cannot tell you

ATT&CK has no structured targeting field. Sector and region are stated only in the prose of each group's description, so the mapping in data/actor_sectors.yaml is extracted from that text and, where the text is truncated or silent, restored by hand from public attribution. Each entry carries its confidence and is open to challenge.

44 of the 232 documented groups and campaigns carry no reliable targeting information and are excluded entirely. Their absence from your profile says nothing about whether they would target you. ATT&CK also documents intrusions that were investigated and published, which over-represents victims with mature incident response — so a short list means the reporting is thin, not that few adversaries care about your sector.

Likely attacks

The model ranks candidates by probability × impact — observed use across 1,057 documented actors, weighted toward the actors you chose, against tactic severity weighted by the crown jewels you declared. Nothing is selected for you.

What this ranking cannot tell you. ATT&CK documents intrusions that were investigated and published, which over-represents victims with mature incident response. A technique rare in ATT&CK is not rare in the world. Treat it as an informed starting point that saves reading 697 technique pages.

Attack paths

Mark the techniques that sit on a modelled route to a crown jewel. This is the attack-tree step reduced to its essence, and it is what separates Tier A — the set worth being excellent at — from everything else.

Start the assessment