Scores & statuses

Scores & statuses

Reference for the statuses, severity and scoring used across BlackNoise results


This page is the single reference for how BlackNoise qualifies events and computes scores. The Dashboard, the campaign Synthesis and the other result views all rely on these definitions.


Detection statuses

Each executed event carries one of four detection statuses:
Status
Status title
Event description

https://slite.com/api/files/PfdtyvxJ1OoU5r/unqualified%20copie.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODUyNTc2MDgsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoiam1IVkg4UWIxRHplUlIiLCJleHAiOjE3ODc4NDk2MDh9.ZmxpD89Rx1xD6QYoSwoH_O1j0gbkuX0WO5qDPgmuAHU
Unqualified
Default status; no detection information has been provided yet.

https://slite.com/api/files/ZdXbS3pBmK8Zl2/undetected-black%20copie.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODUyNTc2MDgsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoiam1IVkg4UWIxRHplUlIiLCJleHAiOjE3ODc4NDk2MDh9.ZmxpD89Rx1xD6QYoSwoH_O1j0gbkuX0WO5qDPgmuAHU

https://slite.com/api/files/lE_MyRODMM05Xp/app.blacknoise.co_campaigns_75666434-f470-4c09-b482-f8cc205ed38d_events_adfe9fb9-755e-43bd-9e63-2d1b88121295%20copie.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODUyNTc2MDgsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoiam1IVkg4UWIxRHplUlIiLCJleHAiOjE3ODc4NDk2MDh9.ZmxpD89Rx1xD6QYoSwoH_O1j0gbkuX0WO5qDPgmuAHU
Undetected

The attack simulation was missed: no log and no alert.

https://slite.com/api/files/wbPcyAiDf1Ey9v/logged-purple%20copie.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODUyNTc2MDgsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoiam1IVkg4UWIxRHplUlIiLCJleHAiOjE3ODc4NDk2MDh9.ZmxpD89Rx1xD6QYoSwoH_O1j0gbkuX0WO5qDPgmuAHU

https://slite.com/api/files/3dHGsus67Okujr/logged-orange%20copie.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODUyNTc2MDgsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoiam1IVkg4UWIxRHplUlIiLCJleHAiOjE3ODc4NDk2MDh9.ZmxpD89Rx1xD6QYoSwoH_O1j0gbkuX0WO5qDPgmuAHU
Logged
The security tools produced a technical trace (a log) for the simulated attack, but no alert was raised and no reaction was taken. To be valid, a Logged proof should indicate at least the source, the destination, the date & time, and if possible the type of action recorded.

https://slite.com/api/files/22Kcrsxdp5C0WN/alerted-purple%20copie.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODUyNTc2MDgsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoiam1IVkg4UWIxRHplUlIiLCJleHAiOjE3ODc4NDk2MDh9.ZmxpD89Rx1xD6QYoSwoH_O1j0gbkuX0WO5qDPgmuAHU

https://slite.com/api/files/B2ikSJ-VlJ8c9G/alerted-green%20copie.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODUyNTc2MDgsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoiam1IVkg4UWIxRHplUlIiLCJleHAiOjE3ODc4NDk2MDh9.ZmxpD89Rx1xD6QYoSwoH_O1j0gbkuX0WO5qDPgmuAHU
Alerted
The security tools identified the simulated attack and raised an alert or a notification. To be valid, an Alerted proof should indicate at least the source, the destination, the date & time, and the type of threat identified. Any remediation applied by the security teams can be recorded in the reaction section.


Reaction statuses

Once an event is detected, its reaction status records whether a response was taken:
  • Reacted — at least one response action (response strategy) has been declared on the event after detection.
  • Ignored — no reaction was recorded after detection.


Exploitation statuses

Complementary to an event's execution status, the exploitation status records the outcome of an adversary action from the attacker's standpoint — independent of whether the action was detected. It takes one of three values:
Status
Status title
Exploitation description
-
Not applicable
The action produces no exploitable result by nature. This is typical of reconnaissance actions (scans, discovery), whose goal is to gather information rather than exploit a weakness.

https://slite.com/api/files/4XJsbQO8ivq3ZR/event_exploitation_status_exploited.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODUyNTc2MDgsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoiam1IVkg4UWIxRHplUlIiLCJleHAiOjE3ODc4NDk2MDh9.ZmxpD89Rx1xD6QYoSwoH_O1j0gbkuX0WO5qDPgmuAHU
Exploited

The action produced the result the attacker intended: the targeted weakness is validated. This is the primary alert signal for the analyst, confirming a real exposure regardless of detection.

https://slite.com/api/files/IgZGEPePmVw7F5/event_exploitation_status_contained.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODUyNTc2MDgsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoiam1IVkg4UWIxRHplUlIiLCJleHAiOjE3ODc4NDk2MDh9.ZmxpD89Rx1xD6QYoSwoH_O1j0gbkuX0WO5qDPgmuAHU
Contained
The action ran as intended but produced no offensive effect, often because a security solution (antivirus, EDR) blocked it. The attacker did not progress.


Severity

Severity flags the events that matter most to detect, on two levels:
  • High (red) — highly critical behavior, given the noise it generates and the impact of the action. Prioritize detecting and reacting to these as fast as possible.
  • Low (yellow) — less important to detect relative to other simulated attacks.


Simplified Kill Chain

BlackNoise groups the MITRE ATT&CK tactics into three phases, used to read detection coverage across the attack lifecycle:
  • Initial access & discovery — Reconnaissance, Resource Development, Initial Access, Credential Access, Discovery.
  • Compromise & lateral movement — Persistence, Privilege Escalation, Defense Evasion, Lateral Movement.
  • Impact & exfiltration — Execution, Collection, Command and Control, Exfiltration, Impact.


Score and grade

How events are scored

BlackNoise scores each event on two criteria:
  • Detection efficiency — the more effective the detection, the higher the score: an Alerted event scores more than a Logged one, which scores more than an Undetected one. A High severity event also scores more than a Low one, reflecting the priority on detecting the most characteristic malicious actions.
  • Detection context — the more information provided about the detection, the higher the score.
The maximum unit score is 12.5 points for a High event and 8.75 points for a Low event (Alerted status with all technical information provided). The overall score is the sum of event points, reported on a 0–100 scale against the maximum achievable:
sum of event points × 100 / (High events × 12.5 + Low events × 8.75)

Simulation grade

A letter grade from E to A+ is assigned from the overall score.
A grade is also computed for each of the three Simplified Kill Chain phases.