What the framework borrows
| Source | Where it does work |
|---|---|
| Palantir Alerting and Detection Strategy Framework | ads.md section names per rule |
| Sigma rule status field | stage marker on every rule file; the Sigma rule itself is the single source each query language is generated from |
| MITRE CTID Summiting the Pyramid | robustness input, 5 levels (anchor wording paraphrased) |
| MITRE ATT&CK | technique field in score.yml, validated by lint; tactic derived by metrics.py from the pinned map Pinned 19.2 (Enterprise) and 19.2 (ICS) on 2026-09-12. |
| MITRE CTID Top ATT&CK Techniques | threat_relevance anchor 3 |
| SAFe Weighted Shortest Job First | formula shape: value over cost |
Open items, verified against primary sources before each release:
- attack: re-run tools/attack_pin.py on each ATT&CK release and review the map diff; v19.2 renamed Defense Evasion to Stealth and added Defense Impairment, and ICS techniques now include T16xx ids
- summiting the pyramid: verify level wording and current version against the CTID primary source
- ctid top attack techniques: verify current list and calculator inputs against the CTID primary source
- sigma status: verify the status value list against the current Sigma specification
- detection engineering maturity matrix: map stages to dimensions from the primary source; unmapped until verified
- acsc cisa priority logs 2025: map the 14 source categories to the telemetry inventory template