# How to Use the ATT&CK Navigator Layer File to Visualize Skill Coverage

> Visualize your cybersecurity skill coverage using the ATT&CK Navigator layer file. Easily map detection gaps and strengths with this interactive heatmap.

- Repository: [Mahipal/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills)
- Tags: how-to-guide
- Published: 2026-05-24

---

**Yes, the repository includes a built-in `generate_navigator_layer` function that converts skill execution results into a MITRE ATT&CK Navigator-compatible JSON layer, allowing you to visualize detection coverage, partial detections, and blind spots as an interactive heat map.**

The `mukul975/Anthropic-Cybersecurity-Skills` repository ships with native support for exporting skill results as an **ATT&CK Navigator layer file**. This capability enables security teams to transform raw atomic-testing logs into visual heat maps that instantly reveal gaps in defensive coverage against the MITRE ATT&CK framework. By mapping detection outcomes to the Navigator's standardized JSON schema, you can generate shareable layers that highlight which techniques are fully protected, partially detected, or complete blind spots.

## How the Layer Generator Maps Detection Results

At the core of this functionality is the `generate_navigator_layer` function implemented in [`skills/performing-purple-team-atomic-testing/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/performing-purple-team-atomic-testing/scripts/agent.py) (lines 36-78). This function consumes three data structures produced after a skill run:

- **`inventory`**: The set of ATT&CK techniques available for testing
- **`execution_logs`**: Records of which atomic tests were actually executed
- **`detection_results`**: Outcomes indicating whether each technique triggered a detection

The generator assigns a **score** and **color** to each technique based on detection confidence:

- **Score 100 / `#66bb6a` (Green)**: High-confidence detection was raised
- **Score 50 / `#ffeb3b` (Yellow)**: Detection exists but confidence is low
- **Score 0 / `#ff6666` (Red)**: Atomic test ran but no detection fired (blind spot)
- **Score 0 / `#d3d3d3` (Gray)**: Technique was not tested at all

The resulting JSON follows the official Navigator v4.5 schema (`"versions": {"attack": "15", "navigator": "5.1", "layer": "4.5"}`) and includes metadata such as test counts, platforms, and execution timestamps that appear as tooltips in the Navigator UI.

## Generating a Navigator Layer from Purple-Team Testing

To create an **ATT&CK Navigator layer file** from a purple-team atomic testing run, use the `--mode navigator` flag or specify a custom filename with `--output-layer`.

Run the following command from the repository root:

```bash
python agent.py \
    --mode navigator \
    --output-layer ./purple_team_coverage.json

```

This invokes the layer generator in [`skills/performing-purple-team-atomic-testing/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/performing-purple-team-atomic-testing/scripts/agent.py), which processes the skill's output directory and writes a JSON file compatible with the Navigator web app. The CLI argument parser defining these options is located at lines 819-824 in the same file.

### Implementation Details

The Python implementation builds the layer dictionary programmatically, as shown in this excerpt from the source:

```python
from datetime import datetime

def generate_navigator_layer(inventory, execution_logs, detection_results,
                             layer_name="Purple Team Coverage"):
    layer = {
        "name": layer_name,
        "versions": {"attack": "15", "navigator": "5.1", "layer": "4.5"},
        "domain": "enterprise-attack",
        "description": f"Generated {datetime.utcnow().isoformat()}Z",
        "techniques": [],
        "gradient": {"colors": ["#ff6666", "#ffeb3b", "#66bb6a"], "minValue": 0, "maxValue": 100},
        "legendItems": [
            {"label": "Blind Spot (tested, no detection)", "color": "#ff6666"},
            {"label": "Partial / Low Confidence", "color": "#ffeb3b"},
            {"label": "Detected (high confidence)", "color": "#66bb6a"},
            {"label": "Not Tested", "color": "#d3d3d3"},
        ],
    }

    for tech_id, tech_data in sorted(inventory.items()):
        was_executed = tech_id in execution_logs
        detection = detection_results.get(tech_id, {})
        was_detected = detection.get("detected", False)
        confidence = detection.get("confidence", "none")

        if was_detected and confidence in ("high", "medium"):
            score, color, comment = 100, "#66bb6a", f"DETECTED [{confidence}]"
        elif was_detected:
            score, color, comment = 50, "#ffeb3b", f"PARTIAL [{confidence}]"
        elif was_executed:
            score, color, comment = 0, "#ff6666", "BLIND SPOT"
        else:
            score, color, comment = 0, "#d3d3d3", f"NOT TESTED - {tech_data['test_count']} tests"

        layer["techniques"].append({
            "techniqueID": tech_id,
            "color": color,
            "comment": comment,
            "score": score,
            "enabled": True,
            "metadata": [
                {"name": "tests_available", "value": str(tech_data["test_count"])},
                {"name": "platforms", "value": ", ".join(tech_data["platforms"])},
                {"name": "executed", "value": str(was_executed)},
                {"name": "detected", "value": str(was_detected)},
            ],
        })
    return layer

```

## Importing and Viewing the Coverage Map

Once you have generated the JSON file, visualize your skill coverage by importing it into the MITRE ATT&CK Navigator:

1. Open the [ATT&CK Navigator web app](https://mitre-attack.github.io/attack-navigator/)
2. Click **"Import Layer"** and select your generated [`navigator_layer.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/navigator_layer.json) (or custom filename)
3. The heat map instantly renders, showing colored cells for each technique based on the scoring logic above
4. Hover over any technique to view detailed metadata including execution status, available atomic tests, and platform coverage

Because the layer adheres to the official Navigator schema, you can also import it into local Navigator installations or merge it with existing layers (such as threat-actor coverage maps) for comparative analysis.

## Extending Coverage Visualization to Other Skills

The repository implements similar layer generation capabilities across multiple skills:

- **[`skills/mapping-mitre-attack-techniques/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/mapping-mitre-attack-techniques/scripts/agent.py)** (lines 119-146): Provides a generic technique-coverage layer generator for mapping exercises
- **[`skills/analyzing-threat-actor-ttps-with-mitre-navigator/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/analyzing-threat-actor-ttps-with-mitre-navigator/scripts/agent.py)** (lines 82-115): Exports threat-actor TTPs as Navigator layers for adversary emulation planning

Each implementation follows the same scoring conventions and schema standards, ensuring consistency across different cybersecurity workflows.

## Summary

- The **ATT&CK Navigator layer file** generator is built into `mukul975/Anthropic-Cybersecurity-Skills` and accessible via `--mode navigator` or `--output-layer` CLI flags
- The `generate_navigator_layer` function in [`skills/performing-purple-team-atomic-testing/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/performing-purple-team-atomic-testing/scripts/agent.py) maps detection results to a four-tier color scheme (green/yellow/red/gray)
- Output files conform to Navigator v4.5 schema standards, compatible with the official web app and local installations
- Layer metadata includes execution logs, test counts, and platform details visible as interactive tooltips
- Multiple skills support layer export, enabling consistent visualization across purple-team testing, technique mapping, and threat-actor analysis

## Frequently Asked Questions

### What schema version does the generated layer file use?

The layer files conform to **Navigator v4.5** with **ATT&CK v15** (`"versions": {"attack": "15", "navigator": "5.1", "layer": "4.5"}`) and target the **enterprise-attack** domain. This ensures compatibility with current versions of the MITRE ATT&CK Navigator web application and allows for seamless importing without conversion errors.

### Can I merge the skill coverage layer with other threat intelligence layers?

**Yes**, because the generated JSON follows the official Navigator schema, you can import it alongside existing layers—such as threat-actor coverage maps or defensive control matrices—and use the Navigator's native layer overlay features to compare your security posture against known adversary behaviors.

### What is the difference between a red cell and a gray cell in the visualization?

Both display **Score 0**, but they indicate different states: **Red (`#ff6666`)** means the atomic test was executed but no detection fired (a blind spot requiring immediate attention), while **Gray (`#d3d3d3`)** indicates the technique was not tested at all, showing coverage gaps in your testing methodology rather than detection failures.

### Where is the ATT&CK Navigator layer file saved by default?

If you use the `--mode navigator` flag without specifying `--output-layer`, the file is written to the skill's output directory with a default name like [`navigator_layer.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/navigator_layer.json). You can override this location by providing a full path to `--output-layer`, for example: `--output-layer ./reports/q3_coverage.json`.