TID-CMM Threat-Informed Detection Capability Maturity Model
Home › Resources

Resources

Everything here is free to use, and every download below belongs to the current release. The current materials are available under the owner’s permitted-use terms; availability is not an open-source grant, and the difference matters, so it is stated rather than implied. No account, no email address, no sales call.

Which release do you need?

Current release

TID-CMM model 1.6.0 · documents v1.6

The current model, the current white paper and workbooks, and the current assessment. This is the version to cite, and the only assessment supported online.

Use current release

Previous release and historical documents

TID-CMM model 1.5.0 · documents v1.4 · site state 20 August 2026

Superseded — historical use only. Preserved so that a report produced under the previous version can be reproduced, an older citation can be checked, and an earlier historical assessment can be understood. It is not a second supported assessment.

Browse previous releases

Everything below this point is the current release.

PDF
White paper (PDF)The full framework: rationale, positioning against SOC-CMM, DEBMM, CTEM and NIST CSF 2.0, the complete model, method, scoring and a worked example. Published as PDF; quote it with the model version.
Download · 1.0 MB
XLSX
Self-assessment workbook17 tabs: setup, eight domain tabs with full 0–5 descriptors as cell comments, all 697 ATT&CK techniques, dashboard with radar chart, ranked roadmap, crosswalk.
Download · 180 KB
XLSX
Worked exampleA completed assessment, pre-filled, so you can see the output before you start.
Download · 185 KB
HTML
Offline assessment toolThe same tool as a single file. Works with no network connection at all.
Download · 642 KB
CSV
ATT&CK technique datasetNormalised ATT&CK Enterprise v19.2: tactics, platforms, data components, detection guidance and mitigations per technique.
Download · 428 KB
CSV
Threat actor profiles1,057 groups, campaigns, malware families and tools with the techniques each uses.
Download · 588 KB
YAML
Threat actor sector mappingWhich sectors and regions each of the 232 documented ATT&CK groups and campaigns is reported against, with a confidence on every entry. 44 carry no reliable targeting information and are marked unknown rather than guessed at. Drives the suggested threat profile.
Download · 39 KB
CSV
Detection strategiesEvery technique's v19.2 detection strategies and analytics with required log sources (1,745 analytics).
Download · 167 KB
YAML
Telemetry catalogueHow to enable the sources carrying the bulk of the analytics: channels, tool class, free route, effort and volume.
Download · 16 KB
JSON
Machine-readable modelThe complete model: domains, sub-capabilities, every level descriptor, evidence criteria, profiles and crosswalks.
Download · 124 KB
JSON
Example scored reportThe worked example as a scored report, including the constraint log.
Download · 31 KB

Licence and permitted use

TID-CMM is free to use under the permissions on the licence page. Assess your own organisation, assess clients for a fee, cite and quote with attribution, and link to the project — none of that needs permission. Republishing the model or the datasets, publishing a derivative, embedding it in another product, rebranding the tool or redistributing the offline build does need written permission, and it is a conversation rather than a refusal.

Free to use does not mean open source, public domain, or permission to redistribute, rebrand or create derivative products. The assessment and site implementation is copyright, all rights reserved. MITRE ATT&CK® content inside the datasets stays governed by MITRE’s own terms. Model 1.5.0 and documents v1.4 keep the licence they were released under.

Licence and permitted use Public model and community on GitHub

Explore the public TID-CMM model, documentation, data and community discussions on GitHub. The assessment implementation and build system are not published there.