Metrics
15 numbers, each defined once and owned by one stage. The repository produces the build-side ones from score.yml and the file layout; the rest come from what analysts record about each alert. The definitions are in Appendix C.
Coverage honesty is the chart the metrics page opens on. On a 30-rule sample program run through the repository's own metrics code, Execution has the most rules and Credential Access has the most weighted coverage:
| Tactic | Live rules | Robustness-weighted |
|---|---|---|
| Execution | 7 | 3.2 |
| Persistence | 5 | 3.0 |
| Privilege Escalation | 5 | 3.0 |
| Credential Access | 4 | 3.4 |
| Stealth | 3 | 1.6 |
| Command and Control | 3 | 0.8 |
| Defense Impairment | 2 | 1.4 |
| Impact | 2 | 1.4 |
| Lateral Movement | 2 | 1.4 |
| Initial Access | 2 | 1.2 |
| Discovery | 2 | 1.0 |
| Exfiltration | 2 | 0.8 |
| Evasion | 1 | 1.0 |
| Impair Process Control | 1 | 1.0 |