TID-CMM Threat-Informed Detection Capability Maturity Model
Home › Methodology › Unknown & emerging threats

Known-Threat Assurance and Unknown-Threat Readiness

TID-CMM scores how well you are prepared for the adversaries you have already named. That is most of the model, and it should be. This page is about the rest: whether the organisation can recognise, investigate and learn from behaviour that falls outside its current assumptions — and why that is a readiness question, never a coverage number.

Everything in an assessment flows from a threat model: the actors you prioritised, the attack paths you drew to your crown jewels, and the ATT&CK behaviours those two things imply. The scope is deliberately an intersection, and the Validated Coverage Score is deliberately computed against that intersection and nothing wider. This is what makes the number honest. It is also what makes it incomplete, and the model should say so rather than let the reader infer that a high score means “we would see anything”.

Two questions, not one score

Known-Threat Assurance asks whether the organisation is prepared for the actors, attack paths and ATT&CK behaviours already prioritised in its threat model. It can be enumerated: the in-scope technique set is a list, every technique on it has a telemetry status, a detection status and a validation status, and the answer is a percentage with a stated denominator. Eight domains, the five constraints and the coverage score all serve this question.

Unknown & Emerging Threat Readiness asks whether the organisation can recognise, investigate and learn from important behaviour that falls outside its current assumptions: a technique nobody prioritised, a procedure ATT&CK has not catalogued yet, an actor not in the profile, a legitimate tool used in a way nobody modelled. It cannot be enumerated, because the thing being asked about is by definition not on the list. There is no denominator. Any figure that claims to be one is a coverage score of the known set wearing a different label.

The model never says “unknown threat coverage”, and neither should an assessor. Unknown threats cannot be counted, so they cannot be covered in the sense the coverage score uses. What can be assessed is readiness: whether the telemetry, the analytics, the people and the feedback loops exist that would turn an unfamiliar behaviour into an investigation, and an investigation into a change to the threat model. Readiness is scored through the sub-capabilities below. It is a view over the model, not a ninth domain.

Two ways in, one machinery

Evidence enters the model in two ways. A known threat arrives as threat evidence, is scoped into techniques and paths, and is answered by detection and validation. An unknown or emerging signal arrives as an anomaly, a hunt finding or a deception interaction, is investigated, and becomes new threat evidence. Correlation, the timeline and the feedback into the threat model serve both; they are not a third kind of threat.

Known threat
  1. threat evidence
  2. scoped techniques
  3. detection and validation
Unknown or emerging signal
  1. anomaly, hunt or deception
  2. investigation
  3. new threat evidence
Both
  1. correlation
  2. timeline
  3. model feedback
Two ways evidence enters the model, one machinery that serves both. Known threats can be scoped and measured; unknown threats cannot be enumerated in advance, so what is measured for them is readiness. Multi-step correlation and the timeline are shared — they are not a third kind of threat.

The comparison

Known-Threat AssuranceUnknown-Threat Readiness
The questionWould we see the adversaries we have prioritised, doing the things they are documented doing, on the paths we drew?Would we notice, investigate and learn from important behaviour we did not prioritise or could not have named?
ScopeThe in-scope technique set: an intersection of platforms, prioritised actors and modelled attack paths. Enumerable.Important behaviour outside current assumptions, or not yet represented by the scoped technique set. It cannot be enumerated completely in advance.
What is measuredPer technique: telemetry reach, detection logic, validation within the recency window. Rolled up into the Validated Coverage Score and the domain scores.Per capability: whether behavioural and deviation detection exists, whether telemetry spans domains, whether hunting is hypothesis-led and continuous, whether anomalies become investigations and investigations become model changes.
Unit of evidenceA named artefact per technique: the rule, the emulation result, the telemetry inventory row.A named artefact per capability: the baseline definition, the hunt library, the deception register, the analytic register with drift records, the case that changed the threat profile.
The outputA percentage with a stated in-scope count, a ranked list of gaps, a roadmap.A statement of readiness against the sub-capabilities below, and a tracked record: how many unfamiliar behaviours were investigated, what each investigation concluded, how many became detections or model changes, and how long the feedback took. Counts, not a rate — there is no denominator.
Where it lives in the modelTI, TM, DC, DE and AV, constrained by C1–C5; the Validated Coverage Score.TI.2, TM.6, DC.2, DC.5, DC.6, DE.6, DE.10, AA.2, AA.4, AA.5, AA.6 and AA.7, read together.
What good looks likeA high coverage score over an honestly scoped set, with validation results inside their window.Unfamiliar behaviour is investigated by a repeatable workflow, its outcomes are tracked, and it reliably changes the threat profile, the models and the detection backlog, with a short and measured time from finding to feedback.
How it failsClaiming coverage without visibility; scoring detection that was never validated; a convenient scope.Treating an anomaly score as a detection; a vendor model nobody understands; hunts that only re-cover known ground; findings that never reach the threat model.

Where readiness already lives in the model

No sub-capability is added for unknown threats, and none should be: readiness is what the existing capabilities look like at their upper levels, where the loop from observation to model change closes. The twelve below carry it. Each links to its full descriptors in the register.

Sub-capabilityWhat it contributes to readinessWhere readiness becomes visible
TI.2 Threat profile and adversary prioritisationThe profile is the boundary of the known. Readiness is whether that boundary moves when reality disagrees with it.Level 4: re-scored against internal telemetry, with recorded downstream tasking. Level 5: includes emerging and unattributed behaviour clusters.
TM.6 Model maintenance and change triggersA significant incident is a defined trigger for model review. An unfamiliar behaviour that reaches the model only through memory is a model that decays.Level 3: incidents and new actors force review, completion tracked. Level 4: drift between model and reality is sampled and reported.
DC.2 Telemetry quality, completeness and timelinessDeviation detection is only as good as the baseline, and the baseline is only as good as the data. Known-gap periods must be recorded, because an anomaly during a gap is an artefact.Level 3: quality measured per source with alerting on deviation. Level 4: known-gap periods recorded and coverage claims adjusted for them.
DC.5 Coverage breadth across attack surfacesAn adversary you did not model will use the surface you did not instrument. Cross-domain telemetry is the precondition for cross-domain correlation.Level 3: per-surface scoping with recorded accepted risk. Level 4: per-surface reporting so endpoint strength cannot mask a blind identity or cloud plane.
DC.6 Visibility gap managementBlind spots are where the unknown lives. A register with owners, priorities and dates is the difference between a tolerated gap and a managed one.Level 3: gaps registered with affected techniques and crown jewels. Level 4: closure rate reported, uncloseable gaps compensated or explicitly accepted.
DE.6 Detection health and silent-failure monitoringA detection that stopped working is a self-inflicted unknown. Silent failure is discovered during an incident, or never.Level 3: health monitored on data availability, schema drift and volume change. Level 5: canary events prove the path end to end.
DE.10 Detection modality breadthA single modality is a single evasion problem. Behaviour that slips past event analytics can still be caught in memory, on the wire, in identity behaviour or on a decoy.Level 3: modalities chosen per behaviour. Level 5: modalities corroborate each other, raising confidence and the cost of evasion.
AA.2 Correlation and attack-chain assemblyWeak signals are what an unmodelled intrusion produces. Readiness is whether they are assembled into an entity, a chain and a timeline rather than triaged one at a time.Level 4: risk-based aggregation of weak signals into scored entities. Level 5: graph correlation reconstructs the path against real topology. See correlation and timeline reconstruction.
AA.4 Advanced analytics governanceBehavioural and statistical analytics are the instruments that see deviation. Ungoverned, they see noise, and drift silently into seeing nothing.Level 3: purpose, targeted behaviour, features and owner documented. Level 4: precision, recall and drift evaluated with a re-baselining cadence.
AA.5 Threat hunting programmeHunting is the deliberate search for what the detections did not catch. Hypothesis-led hunting probes the edges of the threat model; continuous hunting keeps probing as the estate changes.Level 3: hypothesis, scope, method, result and a required output per hunt. Level 4: negative results retained. Level 5: continuous, partly automated, a primary source of the backlog.
AA.6 Case management and knowledge captureAn investigation of unfamiliar behaviour is only readiness if what it learned survives the analyst. Cases are the record that feeds the profile and the backlog.Level 3: mandatory structure including the detection that fired or should have. Level 4: cross-case analysis drives the backlog.
AA.7 Deception and adversary engagementA tripwire fires on the interaction, not on the technique. Deception can expose activity without prior knowledge of the exact procedure, which is why it belongs here — although its placement still depends on understanding the estate and the likely adversary paths.Level 3: placed at attack-tree choke points and along modelled paths. Level 4: coverage of choke points measured, triggers exercised.

What readiness is made of

Behavioural and deviation-based detection

Signature and rule content encodes what is already known. Behavioural detection encodes what is normal for an entity — a user, a service account, a host, a workload — and reports departures from it. The departure is the signal, and the signal is agnostic to technique. That is its strength and its limitation in one sentence: it will fire on a procedure nobody has catalogued, and it will fire on the finance team closing the quarter. A baseline needs a defined population, a defined window, a documented feature set and a recorded false-positive rate, or it is a random number generator with a dashboard.

An anomaly is an investigation lead, not proof of malicious activity. It earns an investigation, an entity, a timeline and a verdict. It does not earn a detection credit, a coverage status, or a line in a board report until a human or a validated analytic has turned it into one.

Cross-domain telemetry

An intrusion that was not modelled will still touch identity, endpoint, network, cloud control plane, SaaS and email — usually several, usually in sequence. Telemetry that concentrates on one surface can only ever see one chapter of it. DC.5 scores breadth deliberately, per surface, so that a strong endpoint programme cannot hide a blind identity plane. Readiness needs the breadth and the normalisation (DC.3) that lets a session on one surface be joined to a process on another.

Multi-modal detection

Event analytics, file and memory content matching, network protocol analysis, identity and entitlement behaviour, integrity monitoring and deception are different instruments with different blind spots. DE.10 scores whether modalities are chosen per behaviour rather than inherited from whichever product was bought first. For behaviour that evades one modality by design, a second modality that corroborates is the difference between a hunch and a case.

Hypothesis-led and continuous hunting

Hunting is the organised search for what the detections missed. At AA.5 level 3 every hunt has a hypothesis drawn from the threat profile, the models, the attack trees or a validation gap, a data scope, a method, a result and a required output. The hypotheses that matter for readiness are the ones at the edge of the model: if an actor we have not prioritised reached this crown jewel, what would the last three steps look like in our data? Continuous hunting — recurring hunts promoted to scheduled analytics, hunts validated against emulation ground truth — is what keeps the edge moving as the estate changes. Negative results are kept, so the same ground is not re-covered blindly.

Deception and tripwires

A canary credential, a decoy share, a honeytoken inside the data an adversary would actually steal. When a deception asset is deliberately placed and governed so that legitimate activity has no reason to touch it, an interaction is a high-confidence signal, whatever technique reached it. It still requires context and verification, and an interaction that turns out to be legitimate must be treated as a possible placement defect rather than dismissed as noise. AA.7 scores placement at attack-tree choke points, refresh so the decoys age like the estate around them, and exercised trigger-to-alert paths. Deception can expose activity without prior knowledge of the exact procedure, although its placement still depends on understanding the estate and the likely adversary paths; the assessment tool credits it as an assurance floor for the techniques a choke point carries, never as telemetry it does not have.

Analytics and model drift

Behavioural analytics decay. The population changes, the estate changes, the adversary learns what the baseline tolerates. AA.4 asks for each analytic to have a documented purpose, a targeted behaviour, named features, an owner, and — at level 4 — measured precision, recall and drift with a re-baselining cadence. An analytic that cannot be explained well enough for an analyst to justify an action on it is not a detection; it is a liability with a licence fee.

Unattributed behaviour clusters

Not every intrusion resolves to a named group, and the profile should not pretend otherwise. TI.2 at level 5 includes emerging and unattributed behaviour clusters: a set of behaviours observed together, in this estate or in sector reporting, that no ATT&CK Group yet explains. A cluster is scoped, hunted and modelled on its own terms until attribution catches up, or does not. Waiting for a name before acting is how an unknown stays unknown for a second quarter.

Internal telemetry feeding the threat profile

The loop closes when what the organisation observed changes what it expects. TI.2 at level 4 re-scores the profile against internal telemetry, not only external reporting, and records the downstream tasking that follows. A behaviour caught by a hunt, a decoy or a baseline that does not end up in the profile, the models (TM.6), the detection backlog and the emulation plan was an incident, not a lesson.

When something unfamiliar fires

Readiness is a workflow before it is a score. This is the one the model expects to find, in a playbook and in case records, when behaviour outside the threat model is found.

  1. Preserve the original telemetry and evidence. Retention windows, rollovers and pipeline drops do not wait for the investigation. Snapshot the raw records before anything else.
  2. Identify affected identities, hosts, workloads, sessions and processes. The entities are the spine of everything that follows.
  3. Correlate related weak signals across domains. The behaviour that fired is rarely the first; look for what preceded it on the same entities and on the surfaces they touched.
  4. Reconstruct the adversary timeline. Order what was observed, mark what was inferred, and mark the blind periods honestly. The correlation and timeline page sets out what that record must contain.
  5. Determine crown-jewel exposure and viable attack paths. Where the entities sit relative to the assets that matter, and which modelled or computed paths run through them (TM.4).
  6. Create temporary hunts, monitoring and detection hypotheses. Look for the same behaviour elsewhere in the estate, and watch the affected entities while the investigation runs.
  7. Validate the behaviour where safely possible. Reproduce it in a controlled way so that a detection can be built against ground truth rather than against one sighting.
  8. Hand prevention and containment to TIR-CMM. Whether the adversary can be stopped, by whom, with what authority and how fast, is the response model’s question. The boundary is drawn on purpose.
  9. Convert the finding into TI, TM, DE and AV work. A profile change, a model change, a detection in the backlog and an emulation case. Four tickets, or it did not happen.
  10. Update the threat model and detection assumptions. The behaviour is now known. The scope moves, the in-scope set changes, and the coverage score is recomputed against a slightly more honest denominator.

Evidence requirements

Readiness is scored through the twelve sub-capabilities, so the evidence is theirs, and C3 applies as it does everywhere: a 4 or a 5 needs a named artefact. The artefacts that speak to readiness specifically:

Where it appears in the tool

The homepage puts the two questions side by side and sends both to the same assessment. On the results page, the Unknown-Threat Readiness view and section D of Assurance at a glance report the relevant sub-capabilities assessed and not assessed, the lowest counted levels, whether evidence text was supplied, and the top improvement actions — as counts and statements, never as a percentage.

Limitations

Readiness cannot be proven the way coverage can. A validated detection is evidence that the tested behaviour was observed under the validated conditions, on the tested surfaces and within the stated evidence window; a hunt library is evidence that someone is looking, not of what they would find. The model therefore scores the capabilities, not the outcome, and an honest report says so.

Behavioural detection has a cost that scales with the quality of the baseline and the patience of the analysts. Where DC.2 is weak the baseline is wrong, and where AA.4 is weak nobody knows how wrong. A readiness claim resting on an ungoverned analytic is not a claim.

Deception only fires where it was placed. It is a high-confidence signal on the modelled paths and silent everywhere else; it extends readiness along the attack trees, not across the estate, and a decoy that legitimate activity keeps touching is a placement defect, not a detection.

And the model cannot see the adversary who leaves no trace in any instrumented surface. That is a visibility gap (DC.6), it belongs on the register with an owner and a date, and no readiness argument closes it.

Common anti-patterns

The Validated Coverage Score · Correlation and timeline reconstruction · Prevention, protection and the TIR-CMM boundary · The 58 sub-capabilities