What the data says

Every figure here comes from benchmark runs whose owners chose to publish them. That is the point of the project: a detection rate on its own means little — next to everybody else’s it means a lot.

No published reports yet — so nothing is claimed yet

The comparison switches on as soon as 3 runs have been shared publicly. Below that, an "average" would be one contributor's posture with a percent sign after it, and publishing it would identify them.

What will appear here

  • The overall detection rate — how often endpoint tooling notices a simulated attack at all.
  • The techniques that get missed most, worst first, sliceable by platform and by product.
  • A product league table: detection rate, most-missed technique, average posture score and health mix per EDR and AV.
  • A product × technique heatmap — which tooling catches which attack.
  • Posture score and grade distributions, and policy compliance.
  • Your own numbers against the baseline, once you have uploaded a run.

Why it is empty rather than approximate

Nothing on these pages is modelled, extrapolated or seeded with example data. With no published reports the honest output is no output.

A group is only shown once 3 separate public reports back it. That threshold applies to every row, every product, and every cell of the heatmap.

Set a run to public when you upload it, and it starts counting. You can change your mind on any report at any time.

How do you compare?

Upload a run and the same figures are computed for you alone, side by side with this baseline — including the techniques where you are ahead and where you are behind.

compare me get the client

Your report stays private unless you mark it public.

How to read these pages

Detection rate is detected + worker killed over every test that produced a verdict; errors and skipped tests leave both sides.

Only published reports are aggregated. Private and organisation-scoped reports never contribute anything here.

Small groups are withheld below 3 reports, and the sample is self-selected, so these figures compare participants rather than the industry.

full methodology