# How Cybersecurity Skills Are Mapped to MITRE D3FEND Defense Strategies

> Discover how cybersecurity skills link to MITRE D3FEND techniques. AI agents use this mapping for efficient, context-aware defense without loading full skill data.

- Repository: [Mahipal/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills)
- Tags: how-to-guide
- Published: 2026-05-24

---

**Each skill in the Anthropic Cybersecurity Skills repository declares MITRE D3FEND technique IDs via the `d3fend_techniques` field in YAML front-matter, enabling AI agents to discover and execute context-appropriate defensive countermeasures without loading full skill bodies until necessary.**

The `mukul975/Anthropic-Cybersecurity-Skills` repository implements a structured framework where individual **cybersecurity skills are mapped to MITRE D3FEND** defensive strategies through a three-layer metadata architecture. This design allows agentskills-compatible runtimes to rapidly identify which defensive techniques a skill implements—such as Process Hardening (`D3-PSMD`) or Memory Analysis (`D3-MA`)—before fetching and executing the complete workflow.

## Three-Layer Mapping Architecture

The repository separates concerns across three distinct layers to maintain both machine efficiency and human auditability.

### Front-Matter Machine-Readable Tags

Each skill’s [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file contains YAML front-matter that follows the agentskills.io standard. The `d3fend_techniques` array provides a machine-readable tag for fast discovery:

```yaml
---
name: performing-memory-forensics-with-volatility3
d3fend_techniques: [D3-MA, D3-PSMD]
atlas_techniques: [AML.T0047]
nist_csf: [DE.CM-01, RS.AN-03]
---

```

These identifiers correspond to official MITRE D3FEND IDs, allowing agents to filter skills by defensive tactic in approximately 30 tokens per skill.

### Reference Documentation for Auditing

Human-readable justification resides in [`references/standards.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/references/standards.md) within each skill directory. This file maps the D3FEND technique IDs to official names and versions (e.g., “Defensive Technique — Process Hardening – v1.3”), ensuring the mapping remains aligned with the official MITRE taxonomy.

### Repository-Wide Coverage Summaries

The root [`README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/README.md) aggregates all `d3fend_techniques` entries across the repository to provide a coverage matrix. According to the source documentation, 11 skills span the seven D3FEND tactical categories, referencing specific techniques from the framework’s total of 267 defensive controls.

## Skill Directory Structure and Implementation Details

The repository organizes each capability as a self-contained directory following this layout:

```text
skills/<skill-name>/
├── SKILL.md          # YAML front-matter + Markdown body

├── references/
│   └── standards.md  # Mapping tables for D3FEND, ATT&CK, ATLAS, NIST CSF

└── scripts/
    └── process.py    # Helper scripts executed by the skill

```

The [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file serves as the authoritative source for D3FEND mapping, while [`references/standards.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/references/standards.md) maintains auditable version tracking of the defensive techniques implemented.

## Runtime Discovery and Execution Flow

When an AI agent receives a request (e.g., “detect lateral movement”), the system executes a three-step workflow:

1. **Scan**: The runtime executes `npx skills add mukul975/Anthropic-Cybersecurity-Skills` to load only the front-matter of every skill, building a lightweight index.
2. **Match**: The incoming query is matched against the `d3fend_techniques` values to identify relevant defensive strategies.
3. **Load**: Upon matching, the agent fetches the full Markdown body, executes the prescribed workflow, and surfaces the D3FEND technique(s) applied in the final report.

This architecture ensures that only skills with relevant defensive mappings consume computational resources during execution.

## Practical Implementation Examples

### Extracting D3FEND Techniques Programmatically

The following Python script demonstrates how an agent can scan the repository to extract every unique D3FEND technique referenced across all skills:

```python
import os
import yaml
from pathlib import Path

repo_root = Path("/__modal/volumes/vo-cSqLfqnnIwYXEonuEJnnZa/repos/github.com/mukul975/Anthropic-Cybersecurity-Skills/main")
skill_dirs = repo_root.glob("skills/*/SKILL.md")

d3fend_set = set()
for skill_path in skill_dirs:
    with open(skill_path, "r") as f:
        # Load only the YAML front-matter (delimited by ---)

        content = f.read()
        front = content.split("---")[1]   # index 1 is the YAML block

        data = yaml.safe_load(front)
        techniques = data.get("d3fend_techniques", [])
        d3fend_set.update(techniques)

print("Unique D3FEND techniques referenced in the repo:")
for tech in sorted(d3fend_set):
    print("- " + tech)

```

This approach mirrors how agentskills-compatible runtimes discover mappings at scale by reading only the front-matter delimiters.

### Executing Skills via CLI with D3FEND Context

To apply a specific defensive technique such as **Process Hardening** (`D3-PSMD`), an agent can invoke the corresponding skill through the CLI:

```bash

# Load the skill library (once per environment)

npx skills add mukul975/Anthropic-Cybersecurity-Skills

# Execute the specific skill; the agent surfaces the D3FEND technique automatically

skills run performing-memory-forensics-with-volatility3 \
  --input memory.dmp \
  --output report.json

```

The execution report includes the mapping from [`references/standards.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/references/standards.md), citing the exact D3FEND technique applied during the operation.

## Essential Files for D3FEND Integration

| File | Role |
|------|------|
| **[`README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/README.md)** | Provides the architectural summary, coverage table showing 11 skills across seven D3FEND categories, and usage instructions. |
| **`skills/<skill-name>/SKILL.md`** | Contains the `d3fend_techniques` field in YAML front-matter used as the core discovery point. |
| **`skills/<skill-name>/references/standards.md`** | Maintains per-skill mapping tables with technique names and versions for audit compliance. |
| **[`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md)** | Displays aggregated repository statistics showing total D3FEND technique coverage. |

## Summary

- **Cybersecurity skills are mapped to MITRE D3FEND** via the `d3fend_techniques` array in the YAML front-matter of each [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file.
- A three-layer architecture separates machine-readable tags (front-matter), human-readable justification ([`references/standards.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/references/standards.md)), and repository-wide coverage metrics ([`README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/README.md)).
- Runtime discovery optimizes performance by scanning only front-matter (approximately 30 tokens per skill) before loading full skill bodies.
- Each skill maintains auditable version tracking of D3FEND techniques, ensuring alignment with the official MITRE taxonomy.

## Frequently Asked Questions

### What is the exact field name used to declare D3FEND techniques in a skill?

The field is `d3fend_techniques`, defined as an array of strings in the YAML front-matter of each [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file. Each element must be a valid MITRE D3FEND identifier, such as `D3-MA` or `D3-PSMD`.

### How does an AI agent determine which D3FEND technique a skill implements?

Agents scan the lightweight front-matter index (approximately 30 tokens per skill) to check for intersection between the query’s defensive requirements and the skill’s `d3fend_techniques` array. Only matching skills have their full Markdown bodies loaded and executed.

### Where is the detailed justification for each D3FEND mapping stored?

Each skill contains a [`references/standards.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/references/standards.md) file that lists the D3FEND technique name and version number (e.g., “Process Hardening – v1.3”). This provides auditable alignment with the official MITRE taxonomy and supports compliance documentation.

### How comprehensive is the D3FEND coverage in this repository?

According to the [`README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/README.md) coverage section, the repository maps 11 distinct skills across the seven D3FEND tactical categories, leveraging specific techniques from the framework’s total catalog of 267 defensive controls.