FIG. 17 Detection coverage

What we actually detect.

Every IronCastle agent release runs the full MITRE Atomic Red Team test suite against a sacrificial endpoint. These are the results — updated weekly, no spin, no curation. The techniques we miss are listed alongside the ones we catch.

Techniques detected
Detection rate
Median time-to-detect
Auto-contained
Last verified
Platform
Loading live coverage data…

Our testing methodology.

Every time we ship a new agent version, an automated CI job provisions a clean macOS virtual machine, installs the IronCastle agent, and runs the full MITRE Atomic Red Team test suite against it. We record which techniques fire a detection, through which layer, and how quickly.

We publish the complete results — including missed techniques — because procurement teams deserve accurate data, not a curated highlight reel. If a gap in coverage matters to your threat model, talk to us. Detection improvements ship weekly.

Sigma YARA Threat Intel Hash Blocklist AI Guardian Missed