Product × technique heatmap
One row per protection product, one column per simulated attacker technique, coloured by detection rate. Greener is better news: the tooling noticed. This is the view that answers “is it just us, or does nothing catch this?”
No published reports yet
The heatmap needs at least 3 published reports behind each cell before it can show anything — and a cell is the smallest group on the site, so it is the last thing to fill in. Run the benchmark and publish the result to start it off.
Reading the heatmap honestly
A row says “machines running this product detected this share of that technique” — not “this product caught it”. Where an EDR and an AV are both installed, both rows get the credit, because the report cannot say which one reacted.
A blank cell means no data or too small a sample, never zero percent. A genuine zero is drawn in the weakest colour bin and reads 0% in the table.
Columns are the most widely run techniques and rows the products with the largest samples, so the matrix stays legible; the full lists live on the technique and product pages.