How Are Skills Mapped to MITRE ATT&CK for Adversary Emulation in Anthropic-Cybersecurity-Skills

The Anthropic-Cybersecurity-Skills repository implements MITRE ATT&CK mappings through three complementary strategies: static category-to-technique dictionaries for incident triage, dynamic STIX-based lookups for coverage analysis, and explicit scenario-to-tactic mappings for red-team engagement planning.

The mukul975/Anthropic-Cybersecurity-Skills repository integrates skills mapped to MITRE ATT&CK for adversary emulation across multiple security workflows. This framework enables security teams to enrich alerts with technique identifiers, calculate detection coverage against the Enterprise matrix, and generate adversary-aligned attack trees for realistic emulation scenarios.

Static Incident Category Mapping

For rapid incident triage without external dependencies, the repository uses a lightweight static mapping approach. This strategy bridges NIST-based incident categories directly to ATT&CK technique IDs through hard-coded lookup tables.

Implementation in build_mitre_mapping()

In skills/triaging-security-incident/scripts/agent.py, the build_mitre_mapping() function (lines 31-55) defines a dictionary that maps alert categories—such as malicious_code or unauthorized_access—to specific ATT&CK technique IDs and names. When the triage agent classifies an incident, it invokes this function to immediately enrich the generated report with relevant ATT&CK context without parsing STIX bundles.

from triaging_security_incident.scripts.agent import build_mitre_mapping

# Classify the incident category

category, _ = classify_incident(alert)

# Retrieve mapped ATT&CK techniques

techniques = build_mitre_mapping(category)

# Returns: [{"technique": "T1110", "name": "Brute Force"}, ...]

This static approach eliminates latency during high-volume triage operations while maintaining alignment with the ATT&CK framework.

Dynamic STIX-Based Technique Analysis

For comprehensive coverage assessment and threat intelligence integration, the repository implements dynamic lookups against the official MITRE ATT&CK STIX dataset.

Loading Enterprise ATT&CK Data

The skills/mapping-mitre-attack-techniques/scripts/agent.py file contains the core STIX interaction logic. The load_attack_data() helper loads the Enterprise ATT&CK bundle (enterprise-attack.json) once per session, caching the dataset for subsequent operations. The get_all_techniques() function extracts the complete technique catalog including IDs, names, tactics, and platforms, while get_techniques_by_group() resolves techniques attributed to specific threat groups like APT29.

Coverage Calculation and Navigator Layers

The calculate_coverage() function compares detected technique IDs (extracted from detection-rule tags) against the full ATT&CK catalog to produce per-tactic coverage percentages. The generate_navigator_layer() function outputs a JSON layer compatible with the MITRE ATT&CK Navigator, enabling visual "heat-map" analysis of detection gaps.

from mapping_mitre_attack_techniques.scripts.agent import (
    load_attack_data, get_all_techniques,
    calculate_coverage, generate_navigator_layer
)

# Initialize STIX data

attack_data = load_attack_data()  # Loads enterprise-attack.json

all_techniques = get_all_techniques(attack_data)

# Example detected techniques from security rules

detected_ids = {"T1059.001", "T1566.001", "T1190"}

# Calculate coverage statistics

coverage_stats = calculate_coverage(all_techniques, detected_ids)

# Generate Navigator layer file

navigator_layer = generate_navigator_layer(
    all_techniques, 
    detected_ids, 
    "SOC Coverage Analysis"
)

Scenario-Based Adversary Emulation Mapping

The red-team engagement planning module maps predefined attack scenarios explicitly to ATT&CK tactics and techniques, enabling structured adversary emulation.

Tactic Enumeration and Attack Trees

In skills/executing-red-team-engagement-planning/scripts/agent.py (lines 12-26), the MITRE_TACTICS list enumerates all 14 ATT&CK tactics. The ATTACK_SCENARIOS dictionary defines specific adversary behaviors—such as phishing or assumed_breach—and lists the concrete technique IDs (e.g., T1566.001, T1204.002) that an emulated adversary will employ.

The generate_attack_tree() routine constructs a step-wise attack path that pairs each technique with its associated tactic. This structured output allows security teams to visualize the engagement plan as a MITRE-aligned attack tree compatible with Navigator or custom simulators.

from executing_red_team_engagement_planning.scripts.agent import (
    MITRE_TACTICS, ATTACK_SCENARIOS,
    generate_engagement_plan, generate_attack_tree
)
import json

# Generate a 6-week engagement plan

plan = generate_engagement_plan(
    client_name="Acme Corp",
    scenarios=["phishing", "assumed_breach"],
    duration_weeks=6,
    team_size=4
)

# Build attack tree for visualization

phishing_tree = generate_attack_tree(ATTACK_SCENARIOS["phishing"])
print(json.dumps(phishing_tree, indent=2))

The tools/validate-skill.py utility ensures all ATT&CK mappings across skills follow the repository's consistency schema, maintaining integrity across static, dynamic, and scenario-based implementations.

Summary

  • Static mapping via build_mitre_mapping() in the triage agent provides immediate technique enrichment for common incident categories without STIX parsing overhead.
  • Dynamic STIX analysis through load_attack_data() and calculate_coverage() enables full-matrix coverage assessment and Navigator layer generation for detection gap analysis.
  • Scenario-based mapping in the red-team module uses explicit tactic/technique pairings to generate adversary-aligned attack trees for emulation planning.
  • All mappings are validated against a common schema via tools/validate-skill.py to ensure consistency across the repository.

Frequently Asked Questions

How does the repository handle static versus dynamic MITRE ATT&CK mappings?

The repository employs both approaches complementarily. Static mappings in skills/triaging-security-incident/scripts/agent.py use hard-coded dictionaries for low-latency incident enrichment, while dynamic mappings in skills/mapping-mitre-attack-techniques/scripts/agent.py parse the official STIX bundle for comprehensive coverage analysis and threat-group correlation.

What file contains the attack tree generation logic for red-team scenarios?

The attack tree generation is implemented in skills/executing-red-team-engagement-planning/scripts/agent.py. The generate_attack_tree() function processes the ATTACK_SCENARIOS definitions to build step-wise attack paths pairing specific techniques with their corresponding tactics.

How is detection coverage calculated against the ATT&CK matrix?

The calculate_coverage() function in the technique mapping agent compares a set of detected technique IDs against the full Enterprise ATT&CK catalog extracted via get_all_techniques(). It returns per-tactic coverage percentages and generates a Navigator-compatible JSON layer through generate_navigator_layer().

Can the tool generate MITRE ATT&CK Navigator layers?

Yes. The generate_navigator_layer() function in skills/mapping-mitre-attack-techniques/scripts/agent.py produces JSON output compatible with the MITRE ATT&CK Navigator, enabling visual heat-map representation of coverage gaps and technique concentrations.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →