Detection-Response Race / Exposure Window (MTTD-vs-MTTC)
Does your monitoring fire before the attacker reaches irreversible impact?
AgentSmack already ships two adjacent blue-team kill-chain lenses: Detectability (MTTD) — when does the first detectable signal fire, and for how many stages did the chain run silently? — and Containment (MTTC) — which reached stages are irreversible, and how hard is the chain to recover from? Neither answers the one go/no-go question a CISO signs off on after a red-team: along the reconstructed kill-chain, does my monitoring fire BEFORE the attacker reaches irreversible impact (a real containment window — the defender wins the race), or does the chain run silent to irreversible harm (window blown)? That is the canonical enterprise detection-vs-impact race: MTTD must beat MTTC. This lens composes the two — it races the first detectable signal against the FIRST irreversible impact (the onset of harm — once the first irreversible action lands there is no window left to contain IT), marks the containment window in stages (positive ⇒ the defender led the first impact; zero ⇒ a dead heat at the first harm; non-positive ⇒ the window was blown), and stays sticky: a silent run to irreversible impact with the tracks covered is unwinnable_evaded at the floor and can never be laundered back to a win. It is honest-empty: no findings reports insufficient_signal, never a fabricated verdict; a chain that never reaches an irreversible stage reports no_irreversible_reached, never a fake race. It adds no new surface and no new scorecard dimension — a pure meta-grade OVER the same findings every scan emits. Fill with a sample run to watch the detection-vs-impact timeline light up with no live infra.
Related read-only meta-lenses over the same findings envelope: Detectability / Dwell-Time (MTTD) · Containment / Recoverability (MTTR) · Attack-Path / Kill-Chain Correlation.