What the framework borrows, and where.
Six outside sources are in use. Each is named once, with the exact place in the framework where it does work.
Stage markers#
A rule's stage is readable from its Sigma status field, and each stage's exit is a named CI job.
| Stage | Sigma status | CI jobs |
|---|
Pin and verify before release#
Every reference is checked against its primary source and version-pinned before a release, the same rule MERIDIAN follows. Open items:
Rendered from framework.json v, CC BY 4.0. ATT&CK pin . Wireframe v0.1, September 2026.