Tiers

Detection tiers

Every rule on this site sits on a rung of David Bianco's Pyramid of Pain, which orders indicators by what it costs an adversary to change them. It is what lets a technique page distinguish "forty rules covering this" from "forty rotating filenames".


Nothing here is a quality judgement. A rule keyed on one domain is not a bad rule; it is a different kind of thing, and mixing it into a comparison misleads.

Two values are ours rather than Bianco's. "Not a detection" covers content that asserts nothing about an adversary, and "Pending classification" is what a rule gets when the classifier declines. The pyramid has a rung for neither.

The rungs

Atomic IOCs a value the adversary owns evasion: trivial to simple
The whole rule is one thing the adversary controls: a domain, an IP, a file hash. It stops working the moment that value rotates. Collapses the pyramid's bottom three rungs, which structure cannot reliably tell apart. Hidden by default: useful for asking 'has anyone seen this?', misleading as a measure of coverage.
Network & Host Artifacts traces the activity leaves evasion: annoying
A URI shape, a user-agent, a registry path. These are the marks left behind when the adversary's tooling runs. Survives the rotation of any single domain or hash; breaks when the tool is reconfigured.
Tools the implement itself evasion: challenging
Identifies the software rather than the traces of it. Most YARA rules sit here, as do Suricata rules keyed on a hardcoded user-agent. Costs the adversary a rebuild or a new tool.
TTPs what the adversary did evasion: tough
Describes the action rather than anything the adversary owns or used: a process spawning another, a sequence of events, a join across other detections. Survives a tool swap, and the rung worth comparing across sources.
Not a detection makes no claim about an adversary
Off the pyramid entirely: asserts configuration, suppresses an alert, enumerates a host, or flags an acceptable-use violation. Ours, not Bianco's. Hidden by default because these detect nothing, not because they are noisy.
Pending classification no rung yet
A classifier read the rule and structure alone did not settle it. Every rule in the index has been examined and none is skipped, so these are held for a later pass rather than guessed at. A wrong rung is worse than none. Concentrated in the formats whose rules say least about what they key on.

How we classify

Every rule is read on its own terms: what it matches on, and what its format can express. A rung is assigned only when the rule itself settles the question.

Nothing is inferred from where a rule came from or who wrote it, and no rung is applied by hand. The same rule always lands in the same place.

51302 of 81687 indexed rules carry a rung. The rest are pending classification, concentrated in the formats that say least about what a rule keys on, or not detections. What each format reveals, and what makes a classifier abstain, is in docs/detection-tiers.md in the repository.

Three things a rung does not tell you

  • How mature your detection programme is. The Pyramid of Pain is per indicator. Stillions' Detection Maturity Level model looks similar and measures something else: an organisation's capability. A ruleset full of TTP rules does not make its operator a mature shop.
  • How hard this particular rule is to evade. The rung says what a rule keys on; how hard that rule is to slip past is a different question, and one we do not answer.
  • Anyone's opinion. Where the evidence runs out a rule stays pending instead of taking the most likely answer, and no rung on the site comes from a list someone maintains.

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.