--cov-fail-under=53 minimum.
This is a pattern-matching engine with ATT&CK mappings — not an ML-based anomaly detector.
--cov-fail-under=53This repository is a rule-based detection/mapping library, not an EDR, SIEM, telemetry collector, or ML anomaly detector. The source README currently labels the documented 42-rule total as unverified until reproduced with the sibling attack-v19-core installed.