A detection lifecycle with countable gates and a scored backlog.
Eight stages, each with an exit you can count. Six numbers that put the backlog in order. Fifteen metrics, each defined once. One data file that the site renders and a repository runs.
LifecycleThe eight stages as a map. Tap a station for its purpose, gate, owner, artifact, and the mistake that stalls it.
PrioritizeScore a backlog by value against cost. Move the weights, watch the order change, export it.
Start hereThree questions that route a team to its first ten rules.
MetricsWhy rule counts overstate coverage, and the fifteen numbers a program reports.
CrosswalkWhat the framework borrows, where each source does work, and what is pinned.
PaperThe framework in one document, with every table generated from the data file.
The reference pipeline is a public repository: one CI job per gate, Sigma in, SPL and KQL out, fixtures replayed in a Splunk container and the Kusto emulator, a score computed for every rule, and ATT&CK pinned at the version the rules were checked against. The data behind every page is at /data/framework.json.