Know what you can see before you write the detection.
Choose a behavior first. Then tell SignalCheck only what telemetry you actually collect. The blueprint builds as you go, showing how each source changes your modeled visibility, which evidence is still weak, and what collection improvement matters next.
DecisionWhat works, what is missing, and what comes next?
STEP 3
YOUR BLUEPRINT BUILDS HERE
Choose a behavior to begin.
SignalCheck starts empty on purpose. Pick the behavior you care about, then add only the telemetry you really collect.
Behavior→Telemetry→Evidence
STEP 3Your detection blueprint
Live model · recalculates with every relevant selection
0
modeled visibility
No telemetry selected
Detection blueprint
Technique
Covered—
Blind spots—
Best next source—
EVIDENCE DEPTH MAP
How strongly your selected sources support each capability
strong partial gap
Go deeper only when you need it.Blueprint explains the gap. Hunt, Detect, and Validate turn it into practitioner action.
Sources, licensing & safety designTransparent by default
MITRE ATT&CK® · v19.2 reviewed
The curated Windows technique set and referenced detection strategies were reviewed against the current ATT&CK v19.2 site on 2026-08-22. Technique identifiers, names, and ATT&CK framing are referenced under MITRE’s ATT&CK Terms of Use. Terms ↗
SigmaHQ
SignalCheck links to upstream SigmaHQ rule discovery rather than redistributing rule bodies. Community rules remain subject to their upstream license and author-attribution requirements. DRL-1.1 ↗
Atomic Red Team™
SignalCheck links to upstream validation catalogs for authorized lab use. SignalCheck never runs tests, commands, agents, or target actions. Project ↗
M3HT4 visibility model
The score is intentionally separate from ATT&CK. It models evidence support from the sources you select, gives more-direct evidence greater weight than contextual sources, and adds corroborating sources with diminishing returns. It does not test whether your collection is enabled, complete, parsed correctly, retained, or alerting.