TID-CMM Threat-Informed Detection Capability Maturity Model
HomeResources

Resources

Everything here is free to use. Two of the three things below are also openly licensed — and the difference matters, so it is stated rather than implied. No account, no email address, no sales call.

PDF
White paper (PDF)The full framework: rationale, positioning against SOC-CMM, DEBMM, CTEM and NIST CSF 2.0, the complete model, method, scoring and a worked example.
Download · 1.1 MB
DOCX
White paper (Word)The same document in editable form, for excerpting into your own material.
Download · 91 KB
XLSX
Self-assessment workbook15 tabs: setup, eight domain tabs with full 0–5 descriptors as cell comments, all 697 ATT&CK techniques, dashboard with radar chart, ranked roadmap, crosswalk.
Download · 173 KB
XLSX
Worked exampleA completed assessment, pre-filled, so you can see the output before you start.
Download · 177 KB
HTML
Offline assessment toolThe same tool as a single file. Works with no network connection at all.
Download · 457 KB
CSV
ATT&CK technique datasetNormalised ATT&CK Enterprise v19.2: tactics, platforms, data components, detection guidance and mitigations per technique.
Download · 428 KB
CSV
Threat actor profiles1,057 groups, campaigns, malware families and tools with the techniques each uses.
Download · 588 KB
YAML
Threat actor sector mappingWhich sectors and regions each of the 232 documented ATT&CK groups and campaigns is reported against, with a confidence on every entry. 44 carry no reliable targeting information and are marked unknown rather than guessed at. Drives the suggested threat profile.
Download · 39 KB
CSV
Detection strategiesEvery technique's v19.2 detection strategies and analytics with required log sources (1,745 analytics).
Download · 167 KB
YAML
Telemetry catalogueHow to enable the sources carrying the bulk of the analytics: channels, tool class, free route, effort and volume.
Download · 16 KB
JSON
Machine-readable modelThe complete model: domains, sub-capabilities, every level descriptor, evidence criteria, profiles and crosswalks.
Download · 124 KB
JSON
Example scored reportOutput of the scoring engine on the worked example, including the constraint log.
Download · 31 KB

Licence — three things, three answers

The project ships an Open Model, Open Data and a Free Assessment Tool. All three cost nothing. Two are openly licensed.

WhatLicenceYou mayYou may not
Open Model
domains, sub-capabilities, level descriptors, weights, evidence criteria, crosswalks, scoring rules
CC BY 4.0 Use commercially, adapt, build products on it, assess clients for a fee — with attributionDrop the attribution
Open Data
derived ATT&CK datasets, telemetry catalogue, conformance vectors, JSON schemas
CC BY 4.0 (ATT&CK content remains © MITRE) Redistribute, transform, embed in your own tooling — with attribution Imply MITRE or this project endorses your product
Free Assessment Tool
the browser tool, the offline HTML build and the Excel workbooks
Free to use — not an open-source licence Use it for anything, including paid client assessment work, unlimited, without askingRedistribute it, rebrand it, or ship derivative tooling from it

Stated as one sentence, because that is the form it will be quoted in: TID-CMM model content and datasets are openly licensed under CC BY 4.0; the assessment tool is free to use, including for commercial assessment work, but is not licensed for redistribution or derivative tooling.

The short version for consultancies and MSSPs: assess your clients with this and charge for it — that is expressly permitted and needs no permission. Rebuild the model into your own product from the open model and data — also permitted, with attribution. What is not permitted is shipping this tool as yours.

MITRE ATT&CK content in the datasets is © The MITRE Corporation and used under the ATT&CK Terms of Use.

Licence and copyright in full — how to attribute, what you may do without asking, and what needs permission.