How Cybersecurity Skills Are Mapped to MITRE D3FEND Defense Strategies
Each skill in the Anthropic Cybersecurity Skills repository declares MITRE D3FEND technique IDs via the d3fend_techniques field in YAML front-matter, enabling AI agents to discover and execute context-appropriate defensive countermeasures without loading full skill bodies until necessary.
The mukul975/Anthropic-Cybersecurity-Skills repository implements a structured framework where individual cybersecurity skills are mapped to MITRE D3FEND defensive strategies through a three-layer metadata architecture. This design allows agentskills-compatible runtimes to rapidly identify which defensive techniques a skill implements—such as Process Hardening (D3-PSMD) or Memory Analysis (D3-MA)—before fetching and executing the complete workflow.
Three-Layer Mapping Architecture
The repository separates concerns across three distinct layers to maintain both machine efficiency and human auditability.
Front-Matter Machine-Readable Tags
Each skill’s SKILL.md file contains YAML front-matter that follows the agentskills.io standard. The d3fend_techniques array provides a machine-readable tag for fast discovery:
---
name: performing-memory-forensics-with-volatility3
d3fend_techniques: [D3-MA, D3-PSMD]
atlas_techniques: [AML.T0047]
nist_csf: [DE.CM-01, RS.AN-03]
---
These identifiers correspond to official MITRE D3FEND IDs, allowing agents to filter skills by defensive tactic in approximately 30 tokens per skill.
Reference Documentation for Auditing
Human-readable justification resides in references/standards.md within each skill directory. This file maps the D3FEND technique IDs to official names and versions (e.g., “Defensive Technique — Process Hardening – v1.3”), ensuring the mapping remains aligned with the official MITRE taxonomy.
Repository-Wide Coverage Summaries
The root README.md aggregates all d3fend_techniques entries across the repository to provide a coverage matrix. According to the source documentation, 11 skills span the seven D3FEND tactical categories, referencing specific techniques from the framework’s total of 267 defensive controls.
Skill Directory Structure and Implementation Details
The repository organizes each capability as a self-contained directory following this layout:
skills/<skill-name>/
├── SKILL.md # YAML front-matter + Markdown body
├── references/
│ └── standards.md # Mapping tables for D3FEND, ATT&CK, ATLAS, NIST CSF
└── scripts/
└── process.py # Helper scripts executed by the skill
The SKILL.md file serves as the authoritative source for D3FEND mapping, while references/standards.md maintains auditable version tracking of the defensive techniques implemented.
Runtime Discovery and Execution Flow
When an AI agent receives a request (e.g., “detect lateral movement”), the system executes a three-step workflow:
- Scan: The runtime executes
npx skills add mukul975/Anthropic-Cybersecurity-Skillsto load only the front-matter of every skill, building a lightweight index. - Match: The incoming query is matched against the
d3fend_techniquesvalues to identify relevant defensive strategies. - Load: Upon matching, the agent fetches the full Markdown body, executes the prescribed workflow, and surfaces the D3FEND technique(s) applied in the final report.
This architecture ensures that only skills with relevant defensive mappings consume computational resources during execution.
Practical Implementation Examples
Extracting D3FEND Techniques Programmatically
The following Python script demonstrates how an agent can scan the repository to extract every unique D3FEND technique referenced across all skills:
import os
import yaml
from pathlib import Path
repo_root = Path("/__modal/volumes/vo-cSqLfqnnIwYXEonuEJnnZa/repos/github.com/mukul975/Anthropic-Cybersecurity-Skills/main")
skill_dirs = repo_root.glob("skills/*/SKILL.md")
d3fend_set = set()
for skill_path in skill_dirs:
with open(skill_path, "r") as f:
# Load only the YAML front-matter (delimited by ---)
content = f.read()
front = content.split("---")[1] # index 1 is the YAML block
data = yaml.safe_load(front)
techniques = data.get("d3fend_techniques", [])
d3fend_set.update(techniques)
print("Unique D3FEND techniques referenced in the repo:")
for tech in sorted(d3fend_set):
print("- " + tech)
This approach mirrors how agentskills-compatible runtimes discover mappings at scale by reading only the front-matter delimiters.
Executing Skills via CLI with D3FEND Context
To apply a specific defensive technique such as Process Hardening (D3-PSMD), an agent can invoke the corresponding skill through the CLI:
# Load the skill library (once per environment)
npx skills add mukul975/Anthropic-Cybersecurity-Skills
# Execute the specific skill; the agent surfaces the D3FEND technique automatically
skills run performing-memory-forensics-with-volatility3 \
--input memory.dmp \
--output report.json
The execution report includes the mapping from references/standards.md, citing the exact D3FEND technique applied during the operation.
Essential Files for D3FEND Integration
| File | Role |
|---|---|
README.md |
Provides the architectural summary, coverage table showing 11 skills across seven D3FEND categories, and usage instructions. |
skills/<skill-name>/SKILL.md |
Contains the d3fend_techniques field in YAML front-matter used as the core discovery point. |
skills/<skill-name>/references/standards.md |
Maintains per-skill mapping tables with technique names and versions for audit compliance. |
ATTACK_COVERAGE.md |
Displays aggregated repository statistics showing total D3FEND technique coverage. |
Summary
- Cybersecurity skills are mapped to MITRE D3FEND via the
d3fend_techniquesarray in the YAML front-matter of eachSKILL.mdfile. - A three-layer architecture separates machine-readable tags (front-matter), human-readable justification (
references/standards.md), and repository-wide coverage metrics (README.md). - Runtime discovery optimizes performance by scanning only front-matter (approximately 30 tokens per skill) before loading full skill bodies.
- Each skill maintains auditable version tracking of D3FEND techniques, ensuring alignment with the official MITRE taxonomy.
Frequently Asked Questions
What is the exact field name used to declare D3FEND techniques in a skill?
The field is d3fend_techniques, defined as an array of strings in the YAML front-matter of each SKILL.md file. Each element must be a valid MITRE D3FEND identifier, such as D3-MA or D3-PSMD.
How does an AI agent determine which D3FEND technique a skill implements?
Agents scan the lightweight front-matter index (approximately 30 tokens per skill) to check for intersection between the query’s defensive requirements and the skill’s d3fend_techniques array. Only matching skills have their full Markdown bodies loaded and executed.
Where is the detailed justification for each D3FEND mapping stored?
Each skill contains a references/standards.md file that lists the D3FEND technique name and version number (e.g., “Process Hardening – v1.3”). This provides auditable alignment with the official MITRE taxonomy and supports compliance documentation.
How comprehensive is the D3FEND coverage in this repository?
According to the README.md coverage section, the repository maps 11 distinct skills across the seven D3FEND tactical categories, leveraging specific techniques from the framework’s total catalog of 267 defensive controls.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →