TID-CMM Threat-Informed Detection Capability Maturity Model
Home › Assessment › Threat scope

Steps 2 to 5 — threat scope

Crown jewels, threat actors, the techniques most likely to be used against you, and the attack paths that make a technique matter.

What these steps establish

These four steps turn a generic catalogue into your catalogue. Scope is an intersection: a technique must be possible on your platforms, used by adversaries you care about, and sit on a path to something worth taking.

Crown jewels

Name what you are protecting and what kind of asset it is — identity, data store, cloud control plane, source code, backups, endpoint fleet, email or OT. The category matters: it determines which tactics are weighted as high impact for you. Declaring domain controllers lifts credential access and lateral movement; declaring backups lifts the ransomware playbook.

Since model 1.6.0 the asset type is a structured choice of sixteen, each mapped to the category the tool has always used, so an assessment saved with an earlier category ranks, scores and exports exactly as before. A type establishes technical relevance: which tactics an adversary must succeed at to reach it, which ATT&CK platforms it is assessed through, which telemetry families see it, which TIR-CMM asset class it maps to, and which scenario templates apply. It never asserts that an adversary targets the asset; actor suggestions stay based on sector and region. A mobile application is assessed through its backend, API, identity and cloud infrastructure, because this dataset is Enterprise ATT&CK and no native Android or iOS coverage is claimed.

Asset typeLegacy categoryATT&CK platformsTelemetry familiesTIR-CMM classScenario templates
Identity and privileged accessIdentity / Active Directory (same weights)Windows, Identity ProviderIdentity and directory auditA1 Identity & Access InfrastructurePhishing to identity dominance
Business and operational dataDatabase / data store (same weights)Windows, Linux, IaaS, SaaSFile, share and object access; Database and application logsA7 Data Stores & BackupCredentialed access to a data store; Ransomware with recovery destruction
Web applicationsOther / not sureLinux, Windows, IaaS, ContainersWeb server and ingress logs; Host telemetry behind the applicationA6 Application, Source & CI/CDPublic-facing application to data
APIs and integrationsOther / not sureLinux, Windows, IaaS, SaaS, ContainersAPI gateway and application logs; Token and key useA6 Application, Source & CI/CDPublic-facing application to data
Mobile applications and mobile backends (assessed through its backend, API, identity and cloud; Enterprise ATT&CK only)Other / not sureLinux, IaaS, SaaS, Identity Provider, ContainersAPI gateway and application logs; Identity and token useA6 Application, Source & CI/CD, A4 Cloud Control Plane & SaaSPublic-facing application to data; SaaS account takeover to mailbox and document theft
SaaS and collaboration platformsOther / not sureSaaS, Office Suite, Identity ProviderTenant audit and sign-in; Collaboration content and sharingA4 Cloud Control Plane & SaaSSaaS account takeover to mailbox and document theft
Email servicesEmail / collaboration (same weights)Office Suite, SaaS, Windows, LinuxMail flow and mailbox auditnoneSaaS account takeover to mailbox and document theft; Endpoint compromise to command and control
Cloud workloadsCloud account / control plane (same weights)IaaS, Containers, Linux, WindowsCloud control-plane audit; Workload and network flowA4 Cloud Control Plane & SaaSCloud control-plane takeover
End-user endpointsEndpoint fleet (same weights)Windows, macOS, LinuxEndpoint process, file and script telemetryA2 Endpoint & User ComputeEndpoint compromise to command and control; Phishing to identity dominance
Servers and data centresOther / not sureWindows, Linux, ESXiServer host telemetry; Hypervisor and managementA3 Server & Datacentre WorkloadRansomware with recovery destruction; Credentialed access to a data store
Network and perimeter infrastructureOther / not sureNetwork DevicesNetwork device audit and configuration; Flow, firewall and DNSA5 Network & EdgeEdge device compromise to internal access
Source code, repositories and CI/CDSource code / build pipeline (same weights)SaaS, Linux, ContainersRepository and pipeline events; Secrets and credential useA6 Application, Source & CI/CDRepository to build pipeline
Data platforms and databasesDatabase / data store (same weights)Linux, Windows, IaaS, SaaSDatabase and query audit; Object storage accessA7 Data Stores & BackupCredentialed access to a data store; Cloud control-plane takeover
Backups and recovery systemsBackups / recovery (same weights)Windows, Linux, IaaSBackup platform and job logs; Host telemetry on backup serversA7 Data Stores & BackupRansomware with recovery destruction
OT, ICS and IoTOT / ICS / physical process (same weights)Windows, Linux, Network DevicesNetwork flow and protocol inspection at the IT/OT boundary; Engineering workstation and jump-host telemetryA8 OT / ICS / IoT / SpecialistIT-to-OT pivot
Other / custom critical serviceOther / not sure——none—

Each declared crown jewel shows what its type changes downstream, and the telemetry step and the roadmap tag every source with the crown jewel it serves. Tactic weights for the new types are on the data model page.

Threat actors

Select the groups and campaigns that plausibly target your sector and geography, from ATT&CK's own actor data. Their combined technique set becomes your candidate pool.

This is where assessments stall. Choosing from 232 documented groups and campaigns with no starting point is the reason scoping gets skipped, and a technique set chosen by tooling rather than by threat is the failure the whole model exists to expose. So the tool offers a suggested threat profile: declare your sector and region on the previous step and it ranks the adversaries ATT&CK documents against organisations like yours, with the reason for each.

Accepting the suggestion unchanged caps TI.2 at level 2. TI.2 asks who you are defending against and how you know. If the tool answered it, you inherited the answer rather than producing it, and constraint C5 records that. The ceiling lifts the moment you engage with the list — add an adversary it missed, remove one that does not apply, or record why you accepted one. The constraint is not there to discourage using the feature; it is there so that using it without thinking cannot look identical to doing the analysis.

What the suggestion cannot tell you

ATT&CK has no structured targeting field. Sector and region are stated only in the prose of each group's description, so the mapping in data/actor_sectors.yaml is extracted from that text and, where the text is truncated or silent, restored by hand from public attribution. Each entry carries its confidence and is open to challenge.

44 of the 232 documented groups and campaigns carry no reliable targeting information and are excluded entirely. Their absence from your profile says nothing about whether they would target you. ATT&CK also documents intrusions that were investigated and published, which over-represents victims with mature incident response — so a short list means the reporting is thin, not that few adversaries care about your sector.

Likely attacks

The model ranks candidates by probability × impact — observed use across 1,057 documented actors, weighted toward the actors you chose, against tactic severity weighted by the crown jewels you declared. Nothing is selected for you.

What this ranking cannot tell you. ATT&CK documents intrusions that were investigated and published, which over-represents victims with mature incident response. A technique rare in ATT&CK is not rare in the world. Treat it as an informed starting point that saves reading 697 technique pages.

Attack paths

Mark the techniques that sit on a modelled route to a crown jewel. This is the attack-tree step reduced to its essence, and it is what separates Tier A — the set worth being excellent at — from everything else.

Start the assessment