detect Introduction

A detection lifecycle with countable gates and a scored backlog.

Eight stages, each with an exit you can count. Six numbers that put the backlog in order. Fifteen metrics, each defined once. One data file that the site renders and a repository runs.

The reference pipeline is a public repository: one CI job per gate, Sigma in, SPL and KQL out, fixtures replayed in a Splunk container and the Kusto emulator, a score computed for every rule, and ATT&CK pinned at the version the rules were checked against. The data behind every page is at /data/framework.json.