Skip to main content

Detection Coverage

Generated: 2026-05-14T12:28:25Z

Headline numbers

  • Curated v1.0 detections: 416 (target: ≥ 300)
  • Total rules considered: 1052 (quality floor: 0.55)
  • Unique MITRE techniques covered: 118

Coverage by buyer family

FamilyCountTargetCovered
Ransomware48≥ 25
Credential Access84≥ 25
Lateral Movement33≥ 25
Data Exfiltration41≥ 25
Cloud100≥ 25
Identity100≥ 25
Supply Chain36≥ 25
Kubernetes / Containers73≥ 25

Distribution

By tier

  • imported: 42
  • native: 374

By severity

  • critical: 99
  • high: 208
  • low: 6
  • medium: 103

By category

  • _migrated: 1
  • application: 29
  • cloud: 164
  • data-exfil: 20
  • endpoint: 117
  • identity: 73
  • network: 12

How to audit

The curated rule IDs are listed in marketplace/curated.json under each family. Every entry has a path field pointing at the on-disk YAML. Run pnpm marketplace:curate --check in CI to enforce drift; run python3 scripts/curate_detections.py locally to regenerate.