# How Are Skills Mapped to MITRE ATT&CK for Adversary Emulation in Anthropic-Cybersecurity-Skills

> Learn how skills map to MITRE ATT&CK for adversary emulation in the Anthropic-Cybersecurity-Skills repository using static dictionaries, dynamic STIX lookups, and explicit scenario mappings.

- Repository: [Mahipal/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills)
- Tags: how-to-guide
- Published: 2026-05-24

---

**The Anthropic-Cybersecurity-Skills repository implements MITRE ATT&CK mappings through three complementary strategies: static category-to-technique dictionaries for incident triage, dynamic STIX-based lookups for coverage analysis, and explicit scenario-to-tactic mappings for red-team engagement planning.**

The `mukul975/Anthropic-Cybersecurity-Skills` repository integrates **skills mapped to MITRE ATT&CK for adversary emulation** across multiple security workflows. This framework enables security teams to enrich alerts with technique identifiers, calculate detection coverage against the Enterprise matrix, and generate adversary-aligned attack trees for realistic emulation scenarios.

## Static Incident Category Mapping

For rapid incident triage without external dependencies, the repository uses a lightweight static mapping approach. This strategy bridges NIST-based incident categories directly to ATT&CK technique IDs through hard-coded lookup tables.

### Implementation in `build_mitre_mapping()`

In [`skills/triaging-security-incident/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/triaging-security-incident/scripts/agent.py), the `build_mitre_mapping()` function (lines 31-55) defines a dictionary that maps alert categories—such as *malicious_code* or *unauthorized_access*—to specific ATT&CK technique IDs and names. When the triage agent classifies an incident, it invokes this function to immediately enrich the generated report with relevant ATT&CK context without parsing STIX bundles.

```python
from triaging_security_incident.scripts.agent import build_mitre_mapping

# Classify the incident category

category, _ = classify_incident(alert)

# Retrieve mapped ATT&CK techniques

techniques = build_mitre_mapping(category)

# Returns: [{"technique": "T1110", "name": "Brute Force"}, ...]

```

This static approach eliminates latency during high-volume triage operations while maintaining alignment with the ATT&CK framework.

## Dynamic STIX-Based Technique Analysis

For comprehensive coverage assessment and threat intelligence integration, the repository implements dynamic lookups against the official MITRE ATT&CK STIX dataset.

### Loading Enterprise ATT&CK Data

The [`skills/mapping-mitre-attack-techniques/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/mapping-mitre-attack-techniques/scripts/agent.py) file contains the core STIX interaction logic. The `load_attack_data()` helper loads the Enterprise ATT&CK bundle ([`enterprise-attack.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/enterprise-attack.json)) once per session, caching the dataset for subsequent operations. The `get_all_techniques()` function extracts the complete technique catalog including IDs, names, tactics, and platforms, while `get_techniques_by_group()` resolves techniques attributed to specific threat groups like *APT29*.

### Coverage Calculation and Navigator Layers

The `calculate_coverage()` function compares detected technique IDs (extracted from detection-rule tags) against the full ATT&CK catalog to produce per-tactic coverage percentages. The `generate_navigator_layer()` function outputs a JSON layer compatible with the MITRE ATT&CK Navigator, enabling visual "heat-map" analysis of detection gaps.

```python
from mapping_mitre_attack_techniques.scripts.agent import (
    load_attack_data, get_all_techniques,
    calculate_coverage, generate_navigator_layer
)

# Initialize STIX data

attack_data = load_attack_data()  # Loads enterprise-attack.json

all_techniques = get_all_techniques(attack_data)

# Example detected techniques from security rules

detected_ids = {"T1059.001", "T1566.001", "T1190"}

# Calculate coverage statistics

coverage_stats = calculate_coverage(all_techniques, detected_ids)

# Generate Navigator layer file

navigator_layer = generate_navigator_layer(
    all_techniques, 
    detected_ids, 
    "SOC Coverage Analysis"
)

```

## Scenario-Based Adversary Emulation Mapping

The red-team engagement planning module maps predefined attack scenarios explicitly to ATT&CK tactics and techniques, enabling structured adversary emulation.

### Tactic Enumeration and Attack Trees

In [`skills/executing-red-team-engagement-planning/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/executing-red-team-engagement-planning/scripts/agent.py) (lines 12-26), the `MITRE_TACTICS` list enumerates all 14 ATT&CK tactics. The `ATTACK_SCENARIOS` dictionary defines specific adversary behaviors—such as *phishing* or *assumed_breach*—and lists the concrete technique IDs (e.g., `T1566.001`, `T1204.002`) that an emulated adversary will employ.

The `generate_attack_tree()` routine constructs a step-wise attack path that pairs each technique with its associated tactic. This structured output allows security teams to visualize the engagement plan as a MITRE-aligned attack tree compatible with Navigator or custom simulators.

```python
from executing_red_team_engagement_planning.scripts.agent import (
    MITRE_TACTICS, ATTACK_SCENARIOS,
    generate_engagement_plan, generate_attack_tree
)
import json

# Generate a 6-week engagement plan

plan = generate_engagement_plan(
    client_name="Acme Corp",
    scenarios=["phishing", "assumed_breach"],
    duration_weeks=6,
    team_size=4
)

# Build attack tree for visualization

phishing_tree = generate_attack_tree(ATTACK_SCENARIOS["phishing"])
print(json.dumps(phishing_tree, indent=2))

```

The [`tools/validate-skill.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/tools/validate-skill.py) utility ensures all ATT&CK mappings across skills follow the repository's consistency schema, maintaining integrity across static, dynamic, and scenario-based implementations.

## Summary

- **Static mapping** via `build_mitre_mapping()` in the triage agent provides immediate technique enrichment for common incident categories without STIX parsing overhead.
- **Dynamic STIX analysis** through `load_attack_data()` and `calculate_coverage()` enables full-matrix coverage assessment and Navigator layer generation for detection gap analysis.
- **Scenario-based mapping** in the red-team module uses explicit tactic/technique pairings to generate adversary-aligned attack trees for emulation planning.
- All mappings are validated against a common schema via [`tools/validate-skill.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/tools/validate-skill.py) to ensure consistency across the repository.

## Frequently Asked Questions

### How does the repository handle static versus dynamic MITRE ATT&CK mappings?

The repository employs both approaches complementarily. Static mappings in [`skills/triaging-security-incident/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/triaging-security-incident/scripts/agent.py) use hard-coded dictionaries for low-latency incident enrichment, while dynamic mappings in [`skills/mapping-mitre-attack-techniques/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/mapping-mitre-attack-techniques/scripts/agent.py) parse the official STIX bundle for comprehensive coverage analysis and threat-group correlation.

### What file contains the attack tree generation logic for red-team scenarios?

The attack tree generation is implemented in [`skills/executing-red-team-engagement-planning/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/executing-red-team-engagement-planning/scripts/agent.py). The `generate_attack_tree()` function processes the `ATTACK_SCENARIOS` definitions to build step-wise attack paths pairing specific techniques with their corresponding tactics.

### How is detection coverage calculated against the ATT&CK matrix?

The `calculate_coverage()` function in the technique mapping agent compares a set of detected technique IDs against the full Enterprise ATT&CK catalog extracted via `get_all_techniques()`. It returns per-tactic coverage percentages and generates a Navigator-compatible JSON layer through `generate_navigator_layer()`.

### Can the tool generate MITRE ATT&CK Navigator layers?

Yes. The `generate_navigator_layer()` function in [`skills/mapping-mitre-attack-techniques/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/mapping-mitre-attack-techniques/scripts/agent.py) produces JSON output compatible with the MITRE ATT&CK Navigator, enabling visual heat-map representation of coverage gaps and technique concentrations.