Which techniques get missed most

Worst first. A high miss rate here means the technique routinely walks past endpoint protection across the whole published sample — not just yours. That is the difference between a gap you own and a gap the whole industry has.

No published reports yet

Per-technique rates need at least 3 published reports behind each technique before they say anything true, so nothing is shown until then.

The techniques the benchmark triggers

Each run attempts a standard set of simulated attacker behaviours — EICAR and inert signature files, known-malware test strings, ransomware-style mass renaming, obfuscated base64 PowerShell, a privileged-user creation attempt, an offensive-tooling download, egress to known-bad networks and TOR, and local subnet scanning. Each one ends in a single outcome, and this page ranks them by how often that outcome was not detected.

The payload set is designed to be extended, so new techniques appear here automatically as the client grows them.

Reading this table

Reports is how many separate published reports ran the technique — the sample size, and what the suppression threshold is applied to. Runs counts executions that produced a verdict.

Miss rate and detection rate do not always sum to 100%: a technique can also be blocked up front, which is neither a miss nor a detection.

Killed workers counts runs where the isolated child process was terminated mid-test. That is the tooling reacting, so it counts as detected — the client runs dangerous tests in a child process precisely so this is measurable.

Your own weakest techniques, against these baselines, are on your comparison page.