ACRE Score Report — 2026-04-13

Scores

PlatformACRE ScoreCovered TechniquesWeighted Score
Windows0.1115 (11.2%)25 / 226 detectable35.0 / 314.0
Linux0.1561 (15.6%)15 / 98 detectable21.0 / 134.5
macOS0.1038 (10.4%)4 / 39 detectable5.5 / 53.0

Detectable threshold: ≥5 open-source rules (Sigma + Splunk + Elastic combined)

Tactic weight (1.5×): persistence, privilege-escalation, defense-evasion, credential-access, discovery, lateral-movement, collection


This is the first run — trend history will appear on the next run after you add detections.


Top Coverage Gaps — Windows

320 total gaps across all platforms.

TechniqueNameWeightSigmaSplunkElastic
T1218System Binary Proxy Execution1.5×1401418
T1027Obfuscated Files or Information1.5×8563
T1055Process Injection1.5×262611
T1087.002Domain Account1.5×21277
T1036Masquerading1.5×34911
T1218.005Mshta1.5×71226
T1098Account Manipulation1.5×161318
T1003OS Credential Dumping1.5×23715
T1068Exploitation for Privilege Escalation1.5×101716
T1133External Remote Services1.5×11311

Top Coverage Gaps — Linux

TechniqueNameWeightSigmaSplunkElastic
T1068Exploitation for Privilege Escalation1.5×5837
T1548.003Sudo and Sudo Caching1.5×03519
T1543Create or Modify System Process1.5×0336
T1574Hijack Execution Flow1.5×0033
T1078Valid Accounts1.5×0232
T1574.006Dynamic Linker Hijacking1.5×2532
T1082System Information Discovery1.5×9523
T1014Rootkit1.5×1322
T1547.006Kernel Modules and Extensions1.5×1720
T1562.001Disable or Modify Tools1.5×3520

Top Coverage Gaps — macOS

TechniqueNameWeightSigmaSplunkElastic
T1087.002Domain Account1.5×0111
T1562.001Disable or Modify Tools1.5×138
T1082System Information Discovery1.5×425
T1133External Remote Services1.5×154
T1110Brute Force1.5×091
T1005Data from Local System1.5×008
T1543.004Launch Daemon1.5×205
T1555.001Keychain1.5×105
T1078.003Local Accounts1.5×405
T1647Plist File Modification1.5×015

Output Files

FileContents
acre_current.jsonToday’s scores
acre_history.jsonHistory (1 entry — baseline established)
acre_gaps.json319 prioritized gaps with rule file paths
parsed_detections.json50 normalized detection records