How to Use the ATT&CK Navigator Layer File to Visualize Skill Coverage

Yes, the repository includes a built-in generate_navigator_layer function that converts skill execution results into a MITRE ATT&CK Navigator-compatible JSON layer, allowing you to visualize detection coverage, partial detections, and blind spots as an interactive heat map.

The mukul975/Anthropic-Cybersecurity-Skills repository ships with native support for exporting skill results as an ATT&CK Navigator layer file. This capability enables security teams to transform raw atomic-testing logs into visual heat maps that instantly reveal gaps in defensive coverage against the MITRE ATT&CK framework. By mapping detection outcomes to the Navigator's standardized JSON schema, you can generate shareable layers that highlight which techniques are fully protected, partially detected, or complete blind spots.

How the Layer Generator Maps Detection Results

At the core of this functionality is the generate_navigator_layer function implemented in skills/performing-purple-team-atomic-testing/scripts/agent.py (lines 36-78). This function consumes three data structures produced after a skill run:

  • inventory: The set of ATT&CK techniques available for testing
  • execution_logs: Records of which atomic tests were actually executed
  • detection_results: Outcomes indicating whether each technique triggered a detection

The generator assigns a score and color to each technique based on detection confidence:

  • Score 100 / #66bb6a (Green): High-confidence detection was raised
  • Score 50 / #ffeb3b (Yellow): Detection exists but confidence is low
  • Score 0 / #ff6666 (Red): Atomic test ran but no detection fired (blind spot)
  • Score 0 / #d3d3d3 (Gray): Technique was not tested at all

The resulting JSON follows the official Navigator v4.5 schema ("versions": {"attack": "15", "navigator": "5.1", "layer": "4.5"}) and includes metadata such as test counts, platforms, and execution timestamps that appear as tooltips in the Navigator UI.

Generating a Navigator Layer from Purple-Team Testing

To create an ATT&CK Navigator layer file from a purple-team atomic testing run, use the --mode navigator flag or specify a custom filename with --output-layer.

Run the following command from the repository root:

python agent.py \
    --mode navigator \
    --output-layer ./purple_team_coverage.json

This invokes the layer generator in skills/performing-purple-team-atomic-testing/scripts/agent.py, which processes the skill's output directory and writes a JSON file compatible with the Navigator web app. The CLI argument parser defining these options is located at lines 819-824 in the same file.

Implementation Details

The Python implementation builds the layer dictionary programmatically, as shown in this excerpt from the source:

from datetime import datetime

def generate_navigator_layer(inventory, execution_logs, detection_results,
                             layer_name="Purple Team Coverage"):
    layer = {
        "name": layer_name,
        "versions": {"attack": "15", "navigator": "5.1", "layer": "4.5"},
        "domain": "enterprise-attack",
        "description": f"Generated {datetime.utcnow().isoformat()}Z",
        "techniques": [],
        "gradient": {"colors": ["#ff6666", "#ffeb3b", "#66bb6a"], "minValue": 0, "maxValue": 100},
        "legendItems": [
            {"label": "Blind Spot (tested, no detection)", "color": "#ff6666"},
            {"label": "Partial / Low Confidence", "color": "#ffeb3b"},
            {"label": "Detected (high confidence)", "color": "#66bb6a"},
            {"label": "Not Tested", "color": "#d3d3d3"},
        ],
    }

    for tech_id, tech_data in sorted(inventory.items()):
        was_executed = tech_id in execution_logs
        detection = detection_results.get(tech_id, {})
        was_detected = detection.get("detected", False)
        confidence = detection.get("confidence", "none")

        if was_detected and confidence in ("high", "medium"):
            score, color, comment = 100, "#66bb6a", f"DETECTED [{confidence}]"
        elif was_detected:
            score, color, comment = 50, "#ffeb3b", f"PARTIAL [{confidence}]"
        elif was_executed:
            score, color, comment = 0, "#ff6666", "BLIND SPOT"
        else:
            score, color, comment = 0, "#d3d3d3", f"NOT TESTED - {tech_data['test_count']} tests"

        layer["techniques"].append({
            "techniqueID": tech_id,
            "color": color,
            "comment": comment,
            "score": score,
            "enabled": True,
            "metadata": [
                {"name": "tests_available", "value": str(tech_data["test_count"])},
                {"name": "platforms", "value": ", ".join(tech_data["platforms"])},
                {"name": "executed", "value": str(was_executed)},
                {"name": "detected", "value": str(was_detected)},
            ],
        })
    return layer

Importing and Viewing the Coverage Map

Once you have generated the JSON file, visualize your skill coverage by importing it into the MITRE ATT&CK Navigator:

  1. Open the ATT&CK Navigator web app
  2. Click "Import Layer" and select your generated navigator_layer.json (or custom filename)
  3. The heat map instantly renders, showing colored cells for each technique based on the scoring logic above
  4. Hover over any technique to view detailed metadata including execution status, available atomic tests, and platform coverage

Because the layer adheres to the official Navigator schema, you can also import it into local Navigator installations or merge it with existing layers (such as threat-actor coverage maps) for comparative analysis.

Extending Coverage Visualization to Other Skills

The repository implements similar layer generation capabilities across multiple skills:

Each implementation follows the same scoring conventions and schema standards, ensuring consistency across different cybersecurity workflows.

Summary

  • The ATT&CK Navigator layer file generator is built into mukul975/Anthropic-Cybersecurity-Skills and accessible via --mode navigator or --output-layer CLI flags
  • The generate_navigator_layer function in skills/performing-purple-team-atomic-testing/scripts/agent.py maps detection results to a four-tier color scheme (green/yellow/red/gray)
  • Output files conform to Navigator v4.5 schema standards, compatible with the official web app and local installations
  • Layer metadata includes execution logs, test counts, and platform details visible as interactive tooltips
  • Multiple skills support layer export, enabling consistent visualization across purple-team testing, technique mapping, and threat-actor analysis

Frequently Asked Questions

What schema version does the generated layer file use?

The layer files conform to Navigator v4.5 with ATT&CK v15 ("versions": {"attack": "15", "navigator": "5.1", "layer": "4.5"}) and target the enterprise-attack domain. This ensures compatibility with current versions of the MITRE ATT&CK Navigator web application and allows for seamless importing without conversion errors.

Can I merge the skill coverage layer with other threat intelligence layers?

Yes, because the generated JSON follows the official Navigator schema, you can import it alongside existing layers—such as threat-actor coverage maps or defensive control matrices—and use the Navigator's native layer overlay features to compare your security posture against known adversary behaviors.

What is the difference between a red cell and a gray cell in the visualization?

Both display Score 0, but they indicate different states: Red (#ff6666) means the atomic test was executed but no detection fired (a blind spot requiring immediate attention), while Gray (#d3d3d3) indicates the technique was not tested at all, showing coverage gaps in your testing methodology rather than detection failures.

Where is the ATT&CK Navigator layer file saved by default?

If you use the --mode navigator flag without specifying --output-layer, the file is written to the skill's output directory with a default name like navigator_layer.json. You can override this location by providing a full path to --output-layer, for example: --output-layer ./reports/q3_coverage.json.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →