Kill-Chain Detectability / Dwell-Time (MTTD)

Would your monitoring have caught this chain, or did it run silently to exfil?

Every other AgentSmack kill-chain lens reasons from the ATTACKER side (exploitability, adversary ROI), the REMEDIATION side (the min-cut that breaks the chain), the IMPACT side (blast radius), or the static control-layering side (defense-in-depth). This is the BLUE-TEAM / SOC lens — the question a CISO actually signs off on after a red-team: would my monitoring have CAUGHT this chain mid-flight, or does it run SILENTLY to exfil — and for how many stages before any detectable signal fired? That is MTTD / dwell-time / detection-evasion — a first-class enterprise security metric. Across the reconstructed kill-chain it marks each reached stage silent (a low-observability foothold / use / privilege gain monitoring rarely catches) versus detectable (a high-observability egress or destructive-action sink that typically tripwires alerts), measures the residual silent window (the dwell before the first detectable signal), and downgrades detectability when an evade finding shows the agent actively covered its tracks. The verdict is sticky — relabeling can never turn an actively-evaded silent run into “caught early” — and honest-empty: no findings reports insufficient_signal, never a fabricated “detected.” It adds no new surface and no new scorecard dimension — a pure detectability grade OVER the same findings every scan emits. Fill with a sample run to watch the stage rail and dwell window light up with no live infra.

Related read-only meta-lenses over the same findings envelope: Containment / Recoverability (MTTR) · Attack-Path / Kill-Chain Correlation · Defense-in-Depth Coverage · Attacker Economics / Adversary ROI.