detect Framework

What the framework borrows

Framework v0.3.0, updated September 19, 2026.

Source Where it does work
Palantir Alerting and Detection Strategy Framework ads.md section names per rule
Sigma rule status field stage marker on every rule file; the Sigma rule itself is the single source each query language is generated from
MITRE CTID Summiting the Pyramid robustness input, 5 levels (anchor wording paraphrased)
MITRE ATT&CK technique field in score.yml, validated by lint; tactic derived by metrics.py from the pinned map Pinned 19.2 (Enterprise) and 19.2 (ICS) on 2026-09-12.
MITRE CTID Top ATT&CK Techniques threat_relevance anchor 3
SAFe Weighted Shortest Job First formula shape: value over cost

Open items, verified against primary sources before each release:

  • attack: re-run tools/attack_pin.py on each ATT&CK release and review the map diff; v19.2 renamed Defense Evasion to Stealth and added Defense Impairment, and ICS techniques now include T16xx ids
  • summiting the pyramid: verify level wording and current version against the CTID primary source
  • ctid top attack techniques: verify current list and calculator inputs against the CTID primary source
  • sigma status: verify the status value list against the current Sigma specification
  • detection engineering maturity matrix: map stages to dimensions from the primary source; unmapped until verified
  • acsc cisa priority logs 2025: map the 14 source categories to the telemetry inventory template