The model
Eight domains, 58 sub-capabilities and 348 level descriptors describing what a threat-informed detection capability looks like at each level of maturity — and five constraints that stop an assessment flattering itself.
Overview
Why rule counts and alert volumes do not measure detection capability, and what the model measures instead.
Eight domains
Threat intelligence, threat modeling, telemetry, detection engineering, adversarial validation, analytics, incident response and governance — with the weight each carries and the question each answers.
58 sub-capabilities
Every sub-capability in the model, its domain, its weight, its applicability profile and the question it asks.
Maturity levels
What each level means in practice, and why level 5 is not a target for most organisations.
Seven principles
The arguments the model enacts rather than merely states: scope is an intersection, capability requires evidence, detection is bounded by visibility, and validation expires.
Relationship to ATT&CK
ATT&CK is consumed, not reproduced. How the in-scope technique set is derived, and why covering all 697 techniques is not the goal.