The eight domains
Each domain is scored 0–5 against explicit descriptors, weighted, and rolled up. Weights are exposed as editable parameters in every tool, because they are a judgement and you should be able to argue with them.
| ID | Domain | Weight | Sub-caps | The question it answers |
|---|---|---|---|---|
| TI | Threat Intelligence & Adversary Prioritisation | 12.0% | 6 | Who are we defending against, and how do we know? |
| TM | Threat Modeling & Attack Path Analysis | 12.0% | 7 | What do their behaviours look like against our architecture? |
| DC | Telemetry & Detection Coverage | 14.0% | 6 | Can we see the activity at all? |
| DE | Detection Engineering | 16.0% | 10 | Do we build, test and maintain detection like engineers? |
| AV | Adversarial Validation & Emulation | 14.0% | 8 | Have we proven any of it works? |
| AA | Analytics, Automation & Hunting | 12.0% | 8 | Does detection output become a decision at operational tempo? |
| IR | Incident Response & Recovery | 10.0% | 6 | Can we act on what we detect? |
| GV | Governance, Metrics & Continuous Improvement | 10.0% | 7 | Is this directed, measured and sustainable? |
On the weights. They encode an argument, not a measurement: detection engineering is the largest continuous body of work, telemetry and validation are where programmes most often fail, and response and governance are necessary but rarely the differentiator. The spread is deliberately narrow — switching to equal weights moves the worked example by 0.01 — because the constraints, not the weights, are where the model does its work.
Each domain in detail
TI — Threat Intelligence & Adversary Prioritisation
12.0% of the overall score 6 sub-capabilities
Who are we defending against, and how do we know?
| ID | Sub-capability | Weight | Profile |
|---|---|---|---|
TI.1 | Intelligence requirements and PIRs | 18.0% | standard |
TI.2 | Threat profile and adversary prioritisation | 20.0% | essential |
TI.3 | Technical CTI ingestion and indicator lifecycle | 14.0% | essential |
TI.4 | TTP extraction and ATT&CK mapping discipline | 18.0% | standard |
TI.5 | Intelligence-to-detection tasking | 18.0% | essential |
TI.6 | Dissemination, sharing and community contribution | 12.0% | comprehensive |
TM — Threat Modeling & Attack Path Analysis
12.0% of the overall score 7 sub-capabilities
What do their behaviours look like against our architecture?
| ID | Sub-capability | Weight | Profile |
|---|---|---|---|
TM.1 | Asset, identity and crown-jewel identification | 13.0% | essential |
TM.2 | System and data-flow threat modeling | 16.0% | standard |
TM.7 | Attack surface enumeration | 14.0% | essential |
TM.3 | Attack tree construction | 16.0% | standard |
TM.4 | Attack path and exposure analysis | 15.0% | comprehensive |
TM.5 | Abuse cases to detection requirements traceability | 14.0% | standard |
TM.6 | Model maintenance and change triggers | 12.0% | comprehensive |
DC — Telemetry & Detection Coverage
14.0% of the overall score 6 sub-capabilities
Can we see the activity at all?
| ID | Sub-capability | Weight | Profile |
|---|---|---|---|
DC.1 | Log source inventory and ownership | 14.0% | essential |
DC.2 | Telemetry quality, completeness and timeliness | 18.0% | essential |
DC.3 | Normalisation and data model discipline | 14.0% | standard |
DC.4 | ATT&CK technique coverage measurement | 20.0% | standard |
DC.5 | Coverage breadth across attack surfaces | 20.0% | essential |
DC.6 | Visibility gap management | 14.0% | essential |
DE — Detection Engineering
16.0% of the overall score 10 sub-capabilities
Do we build, test and maintain detection like engineers?
| ID | Sub-capability | Weight | Profile |
|---|---|---|---|
DE.1 | Detection lifecycle and intake | 10.0% | essential |
DE.2 | Detection-as-code | 12.0% | standard |
DE.3 | Detection standards, metadata and documentation | 10.0% | essential |
DE.4 | Testing and pre-deployment validation | 13.0% | standard |
DE.5 | Tuning, precision and false-positive management | 10.0% | essential |
DE.6 | Detection health and silent-failure monitoring | 10.0% | essential |
DE.7 | Versioning, deprecation and retirement | 8.0% | standard |
DE.8 | Portfolio composition and detection strategy | 12.0% | standard |
DE.9 | Detection content sourcing and provenance | 8.0% | essential |
DE.10 | Detection modality breadth | 7.0% | standard |
AV — Adversarial Validation & Emulation
14.0% of the overall score 8 sub-capabilities
Have we proven any of it works?
| ID | Sub-capability | Weight | Profile |
|---|---|---|---|
AV.1 | Atomic testing and control verification | 13.0% | essential |
AV.2 | Breach and attack simulation automation | 12.0% | standard |
AV.3 | Threat-actor emulation plans | 15.0% | comprehensive |
AV.4 | Purple team programme | 13.0% | comprehensive |
AV.5 | Penetration testing integration | 12.0% | standard |
AV.6 | Red teaming and independent assurance | 12.0% | comprehensive |
AV.7 | Findings-to-closure loop | 13.0% | standard |
AV.8 | Control efficacy scoring | 10.0% | comprehensive |
AA — Analytics, Automation & Hunting
12.0% of the overall score 8 sub-capabilities
Does detection output become a decision at operational tempo?
| ID | Sub-capability | Weight | Profile |
|---|---|---|---|
AA.1 | Triage enrichment and context automation | 13.0% | essential |
AA.2 | Correlation and attack-chain assembly | 14.0% | standard |
AA.3 | Response automation and orchestration | 12.0% | standard |
AA.4 | Advanced analytics governance | 11.0% | comprehensive |
AA.5 | Threat hunting programme | 15.0% | standard |
AA.7 | Deception and adversary engagement | 13.0% | standard |
AA.6 | Case management and knowledge capture | 11.0% | essential |
AA.8 | Agentic and AI-assisted operations | 11.0% | standard |
IR — Incident Response & Recovery
10.0% of the overall score 6 sub-capabilities
Can we act on what we detect?
| ID | Sub-capability | Weight | Profile |
|---|---|---|---|
IR.1 | Response plan, playbooks and readiness | 18.0% | essential |
IR.2 | Detection-to-response handoff and SLAs | 17.0% | essential |
IR.3 | Forensic readiness and evidence handling | 15.0% | standard |
IR.4 | Containment, eradication and recovery | 17.0% | standard |
IR.5 | Exercising and crisis management | 16.0% | standard |
IR.6 | Post-incident review to detection backlog | 17.0% | essential |
GV — Governance, Metrics & Continuous Improvement
10.0% of the overall score 7 sub-capabilities
Is this directed, measured and sustainable?
| ID | Sub-capability | Weight | Profile |
|---|---|---|---|
GV.1 | Strategy, mandate and funding | 15.0% | essential |
GV.2 | Roles, skills and capability development | 15.0% | standard |
GV.3 | Metrics and performance measurement | 18.0% | essential |
GV.4 | Risk and compliance alignment | 14.0% | standard |
GV.5 | Executive and board reporting | 13.0% | standard |
GV.6 | Continuous improvement cadence | 13.0% | standard |
GV.7 | Third-party and supply-chain detection | 12.0% | comprehensive |