# Most Covered Security Domains in the Anthropic Cybersecurity Skills Repository

> Discover the most covered security domains in the Anthropic Cybersecurity Skills repository. Learn about defense evasion and persistence techniques.

- Repository: [Mahipal/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills)
- Tags: deep-dive
- Published: 2026-05-24

---

**Defense Evasion and Persistence are the most covered security domains** in the Anthropic Cybersecurity Skills repository, with 48 and 36 MITRE ATT&CK techniques respectively.

The Anthropic Cybersecurity Skills repository aligns every skill with the MITRE ATT&CK framework to create a structured defensive curriculum. Understanding which security domains receive the most coverage helps practitioners prioritize learning paths and identify gaps in detection capabilities. This analysis examines the repository's generated coverage map to reveal how the 753+ skills distribute across the ATT&CK matrix.

## Top Security Domains by ATT&CK Coverage

The repository's [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md) file provides a data-driven view of technique distribution across tactics. The following table shows the technique count for each security domain:

| Security Domain (Tactic) | Techniques Covered |
|--------------------------|-------------------|
| **Defense Evasion** | 48 |
| **Persistence** | 36 |
| **Credential Access** | 27 |
| **Command & Control** | 20 |
| **Discovery** | 20 |
| **Initial Access** | 18 |
| **Execution** | 18 |
| **Collection** | 13 |
| **Reconnaissance** | 12 |
| **Exfiltration** | 12 |
| **Resource Development** | 7 |
| **Impact** | 6 |
| **Lateral Movement** | 9 |

**Defense Evasion** dominates the coverage with 48 unique techniques, indicating a strong emphasis on detecting and mitigating methods that adversaries use to hide their presence. **Persistence** follows with 36 techniques, reflecting the repository's focus on identifying backdoors and maintaining access vectors. These two domains together account for the majority of the curriculum's defensive depth.

## How Coverage Is Tracked in the Repository

### Skill Structure and ATT&CK Mapping

Each skill resides in `skills/<skill-name>/` and contains a [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) description, an [`api-reference.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/api-reference.md) file, and executable Python scripts such as [`agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/agent.py) and [`process.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/process.py). The repository maintains a central JSON index at [`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json) that maps every skill to specific MITRE ATT&CK technique IDs, creating a machine-readable relationship between instructional content and the framework.

### Coverage Generation Pipeline

The helper script [`tools/validate-skill.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/tools/validate-skill.py) automates coverage analysis by walking the [`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json) file, aggregating technique counts per tactic, and writing the human-readable summary to [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md). This architecture ensures that when contributors add new skills, the security domain statistics update automatically without manual editing. The script also validates that each skill references a known ATT&CK technique, preventing orphaned entries in the coverage map.

## Querying Coverage Data Programmatically

You can extract domain coverage statistics directly from [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md) to integrate with dashboards or CI pipelines. The following Python snippet parses the generated markdown and prints the top three tactics by technique count:

```python
import pathlib
import re
from collections import Counter

# Path to the generated coverage markdown (repo root)

coverage_path = pathlib.Path('ATTACK_COVERAGE.md')

# Extract lines that contain the tactic bar‑graph

pattern = re.compile(r'\|\s*([^\|]+?)\s*\|\s*\*\*(\d+)\*\s*\|')
tactic_counts = Counter()

with coverage_path.open() as f:
    for line in f:
        m = pattern.search(line)
        if m:
            tactic, count = m.group(1).strip(), int(m.group(2))
            tactic_counts[tactic] = count

# Show the three most covered domains

for tactic, cnt in tactic_counts.most_common(3):
    print(f'{tactic}: {cnt} techniques')

```

Running this script in the repository root yields:

```

🛡️ Defense Evasion: 48 techniques
🔩 Persistence: 36 techniques
🔑 Credential Access: 27 techniques

```

This approach allows security teams to consume the coverage data programmatically without parsing the entire skill set or [`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json) structure.

## Key Files for Understanding Domain Coverage

- **[`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md)** — Located at the repository root, this file contains the human-readable summary table with Unicode bar graphs showing relative coverage across all security domains.

- **[`mappings/mitre-attack/coverage-summary.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/mappings/mitre-attack/coverage-summary.md)** — Provides the raw mapping of each ATT&CK technique to the list of skills that implement it, serving as the source of truth for coverage calculations.

- **[`tools/validate-skill.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/tools/validate-skill.py)** — The validation and generation script that aggregates technique counts per domain from [`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json) and ensures all ATT&CK references are valid.

- **[`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json)** — The central JSON document recording skill-to-technique relationships, automatically updated when new skills are added to the repository.

## Summary

- **Defense Evasion** is the most covered security domain with 48 ATT&CK techniques, followed by **Persistence** with 36 techniques.
- Coverage statistics are auto-generated from [`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json) via [`tools/validate-skill.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/tools/validate-skill.py) and published to [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md).
- The repository contains 753+ skills mapped to specific MITRE ATT&CK technique IDs.
- Significant coverage gaps remain in **Impact** (6 techniques) and **Resource Development** (7 techniques).
- Practitioners can query [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md) programmatically to track domain statistics and identify learning priorities.

## Frequently Asked Questions

### Which security domain has the highest coverage in the repository?

**Defense Evasion** is the most covered security domain with 48 unique MITRE ATT&CK techniques implemented across the skill set. This emphasis targets the detection of techniques adversaries use to avoid defenses and hide malicious activity within enterprise environments.

### How is the coverage data generated and maintained?

Coverage data is generated automatically by the [`tools/validate-skill.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/tools/validate-skill.py) script, which parses [`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json) to aggregate technique counts per tactic. The script outputs the human-readable table to [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md), ensuring that security domain statistics remain synchronized with the actual skill content without manual intervention.

### Where can I find the raw mapping between skills and ATT&CK techniques?

The detailed mapping resides in [`mappings/mitre-attack/coverage-summary.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/mappings/mitre-attack/coverage-summary.md), which lists each ATT&CK technique alongside the specific skills that cover it. This file serves as the underlying data source for the high-level percentages shown in the main [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md) dashboard.

### Why do some security domains like Impact have lower coverage?

**Impact** contains only 6 covered techniques, representing a deliberate curriculum gap. According to the repository's architecture, the skill set prioritizes pre-compromise detection capabilities—specifically **Defense Evasion** and **Persistence**—over post-compromise impact analysis, though the modular skill structure allows for future expansion into these areas.