TID-CMM Threat-Informed Detection Capability Maturity Model
HomeModelEight domains

The eight domains

Each domain is scored 0–5 against explicit descriptors, weighted, and rolled up. Weights are exposed as editable parameters in every tool, because they are a judgement and you should be able to argue with them.

IDDomainWeightSub-caps The question it answers
TIThreat Intelligence & Adversary Prioritisation12.0%6Who are we defending against, and how do we know?
TMThreat Modeling & Attack Path Analysis12.0%7What do their behaviours look like against our architecture?
DCTelemetry & Detection Coverage14.0%6Can we see the activity at all?
DEDetection Engineering16.0%10Do we build, test and maintain detection like engineers?
AVAdversarial Validation & Emulation14.0%8Have we proven any of it works?
AAAnalytics, Automation & Hunting12.0%8Does detection output become a decision at operational tempo?
IRIncident Response & Recovery10.0%6Can we act on what we detect?
GVGovernance, Metrics & Continuous Improvement10.0%7Is this directed, measured and sustainable?

On the weights. They encode an argument, not a measurement: detection engineering is the largest continuous body of work, telemetry and validation are where programmes most often fail, and response and governance are necessary but rarely the differentiator. The spread is deliberately narrow — switching to equal weights moves the worked example by 0.01 — because the constraints, not the weights, are where the model does its work.

Each domain in detail

TI — Threat Intelligence & Adversary Prioritisation

12.0% of the overall score 6 sub-capabilities

Who are we defending against, and how do we know?

IDSub-capabilityWeightProfile
TI.1Intelligence requirements and PIRs18.0%standard
TI.2Threat profile and adversary prioritisation20.0%essential
TI.3Technical CTI ingestion and indicator lifecycle14.0%essential
TI.4TTP extraction and ATT&CK mapping discipline18.0%standard
TI.5Intelligence-to-detection tasking18.0%essential
TI.6Dissemination, sharing and community contribution12.0%comprehensive

TM — Threat Modeling & Attack Path Analysis

12.0% of the overall score 7 sub-capabilities

What do their behaviours look like against our architecture?

IDSub-capabilityWeightProfile
TM.1Asset, identity and crown-jewel identification13.0%essential
TM.2System and data-flow threat modeling16.0%standard
TM.7Attack surface enumeration14.0%essential
TM.3Attack tree construction16.0%standard
TM.4Attack path and exposure analysis15.0%comprehensive
TM.5Abuse cases to detection requirements traceability14.0%standard
TM.6Model maintenance and change triggers12.0%comprehensive

DC — Telemetry & Detection Coverage

14.0% of the overall score 6 sub-capabilities

Can we see the activity at all?

IDSub-capabilityWeightProfile
DC.1Log source inventory and ownership14.0%essential
DC.2Telemetry quality, completeness and timeliness18.0%essential
DC.3Normalisation and data model discipline14.0%standard
DC.4ATT&CK technique coverage measurement20.0%standard
DC.5Coverage breadth across attack surfaces20.0%essential
DC.6Visibility gap management14.0%essential

DE — Detection Engineering

16.0% of the overall score 10 sub-capabilities

Do we build, test and maintain detection like engineers?

IDSub-capabilityWeightProfile
DE.1Detection lifecycle and intake10.0%essential
DE.2Detection-as-code12.0%standard
DE.3Detection standards, metadata and documentation10.0%essential
DE.4Testing and pre-deployment validation13.0%standard
DE.5Tuning, precision and false-positive management10.0%essential
DE.6Detection health and silent-failure monitoring10.0%essential
DE.7Versioning, deprecation and retirement8.0%standard
DE.8Portfolio composition and detection strategy12.0%standard
DE.9Detection content sourcing and provenance8.0%essential
DE.10Detection modality breadth7.0%standard

AV — Adversarial Validation & Emulation

14.0% of the overall score 8 sub-capabilities

Have we proven any of it works?

IDSub-capabilityWeightProfile
AV.1Atomic testing and control verification13.0%essential
AV.2Breach and attack simulation automation12.0%standard
AV.3Threat-actor emulation plans15.0%comprehensive
AV.4Purple team programme13.0%comprehensive
AV.5Penetration testing integration12.0%standard
AV.6Red teaming and independent assurance12.0%comprehensive
AV.7Findings-to-closure loop13.0%standard
AV.8Control efficacy scoring10.0%comprehensive

AA — Analytics, Automation & Hunting

12.0% of the overall score 8 sub-capabilities

Does detection output become a decision at operational tempo?

IDSub-capabilityWeightProfile
AA.1Triage enrichment and context automation13.0%essential
AA.2Correlation and attack-chain assembly14.0%standard
AA.3Response automation and orchestration12.0%standard
AA.4Advanced analytics governance11.0%comprehensive
AA.5Threat hunting programme15.0%standard
AA.7Deception and adversary engagement13.0%standard
AA.6Case management and knowledge capture11.0%essential
AA.8Agentic and AI-assisted operations11.0%standard

IR — Incident Response & Recovery

10.0% of the overall score 6 sub-capabilities

Can we act on what we detect?

IDSub-capabilityWeightProfile
IR.1Response plan, playbooks and readiness18.0%essential
IR.2Detection-to-response handoff and SLAs17.0%essential
IR.3Forensic readiness and evidence handling15.0%standard
IR.4Containment, eradication and recovery17.0%standard
IR.5Exercising and crisis management16.0%standard
IR.6Post-incident review to detection backlog17.0%essential

GV — Governance, Metrics & Continuous Improvement

10.0% of the overall score 7 sub-capabilities

Is this directed, measured and sustainable?

IDSub-capabilityWeightProfile
GV.1Strategy, mandate and funding15.0%essential
GV.2Roles, skills and capability development15.0%standard
GV.3Metrics and performance measurement18.0%essential
GV.4Risk and compliance alignment14.0%standard
GV.5Executive and board reporting13.0%standard
GV.6Continuous improvement cadence13.0%standard
GV.7Third-party and supply-chain detection12.0%comprehensive