Most Covered Security Domains in the Anthropic Cybersecurity Skills Repository

Defense Evasion and Persistence are the most covered security domains in the Anthropic Cybersecurity Skills repository, with 48 and 36 MITRE ATT&CK techniques respectively.

The Anthropic Cybersecurity Skills repository aligns every skill with the MITRE ATT&CK framework to create a structured defensive curriculum. Understanding which security domains receive the most coverage helps practitioners prioritize learning paths and identify gaps in detection capabilities. This analysis examines the repository's generated coverage map to reveal how the 753+ skills distribute across the ATT&CK matrix.

Top Security Domains by ATT&CK Coverage

The repository's ATTACK_COVERAGE.md file provides a data-driven view of technique distribution across tactics. The following table shows the technique count for each security domain:

Security Domain (Tactic) Techniques Covered
Defense Evasion 48
Persistence 36
Credential Access 27
Command & Control 20
Discovery 20
Initial Access 18
Execution 18
Collection 13
Reconnaissance 12
Exfiltration 12
Resource Development 7
Impact 6
Lateral Movement 9

Defense Evasion dominates the coverage with 48 unique techniques, indicating a strong emphasis on detecting and mitigating methods that adversaries use to hide their presence. Persistence follows with 36 techniques, reflecting the repository's focus on identifying backdoors and maintaining access vectors. These two domains together account for the majority of the curriculum's defensive depth.

How Coverage Is Tracked in the Repository

Skill Structure and ATT&CK Mapping

Each skill resides in skills/<skill-name>/ and contains a SKILL.md description, an api-reference.md file, and executable Python scripts such as agent.py and process.py. The repository maintains a central JSON index at index.json that maps every skill to specific MITRE ATT&CK technique IDs, creating a machine-readable relationship between instructional content and the framework.

Coverage Generation Pipeline

The helper script tools/validate-skill.py automates coverage analysis by walking the index.json file, aggregating technique counts per tactic, and writing the human-readable summary to ATTACK_COVERAGE.md. This architecture ensures that when contributors add new skills, the security domain statistics update automatically without manual editing. The script also validates that each skill references a known ATT&CK technique, preventing orphaned entries in the coverage map.

Querying Coverage Data Programmatically

You can extract domain coverage statistics directly from ATTACK_COVERAGE.md to integrate with dashboards or CI pipelines. The following Python snippet parses the generated markdown and prints the top three tactics by technique count:

import pathlib
import re
from collections import Counter

# Path to the generated coverage markdown (repo root)

coverage_path = pathlib.Path('ATTACK_COVERAGE.md')

# Extract lines that contain the tactic bar‑graph

pattern = re.compile(r'\|\s*([^\|]+?)\s*\|\s*\*\*(\d+)\*\s*\|')
tactic_counts = Counter()

with coverage_path.open() as f:
    for line in f:
        m = pattern.search(line)
        if m:
            tactic, count = m.group(1).strip(), int(m.group(2))
            tactic_counts[tactic] = count

# Show the three most covered domains

for tactic, cnt in tactic_counts.most_common(3):
    print(f'{tactic}: {cnt} techniques')

Running this script in the repository root yields:


🛡️ Defense Evasion: 48 techniques
🔩 Persistence: 36 techniques
🔑 Credential Access: 27 techniques

This approach allows security teams to consume the coverage data programmatically without parsing the entire skill set or index.json structure.

Key Files for Understanding Domain Coverage

  • ATTACK_COVERAGE.md — Located at the repository root, this file contains the human-readable summary table with Unicode bar graphs showing relative coverage across all security domains.

  • mappings/mitre-attack/coverage-summary.md — Provides the raw mapping of each ATT&CK technique to the list of skills that implement it, serving as the source of truth for coverage calculations.

  • tools/validate-skill.py — The validation and generation script that aggregates technique counts per domain from index.json and ensures all ATT&CK references are valid.

  • index.json — The central JSON document recording skill-to-technique relationships, automatically updated when new skills are added to the repository.

Summary

  • Defense Evasion is the most covered security domain with 48 ATT&CK techniques, followed by Persistence with 36 techniques.
  • Coverage statistics are auto-generated from index.json via tools/validate-skill.py and published to ATTACK_COVERAGE.md.
  • The repository contains 753+ skills mapped to specific MITRE ATT&CK technique IDs.
  • Significant coverage gaps remain in Impact (6 techniques) and Resource Development (7 techniques).
  • Practitioners can query ATTACK_COVERAGE.md programmatically to track domain statistics and identify learning priorities.

Frequently Asked Questions

Which security domain has the highest coverage in the repository?

Defense Evasion is the most covered security domain with 48 unique MITRE ATT&CK techniques implemented across the skill set. This emphasis targets the detection of techniques adversaries use to avoid defenses and hide malicious activity within enterprise environments.

How is the coverage data generated and maintained?

Coverage data is generated automatically by the tools/validate-skill.py script, which parses index.json to aggregate technique counts per tactic. The script outputs the human-readable table to ATTACK_COVERAGE.md, ensuring that security domain statistics remain synchronized with the actual skill content without manual intervention.

Where can I find the raw mapping between skills and ATT&CK techniques?

The detailed mapping resides in mappings/mitre-attack/coverage-summary.md, which lists each ATT&CK technique alongside the specific skills that cover it. This file serves as the underlying data source for the high-level percentages shown in the main ATTACK_COVERAGE.md dashboard.

Why do some security domains like Impact have lower coverage?

Impact contains only 6 covered techniques, representing a deliberate curriculum gap. According to the repository's architecture, the skill set prioritizes pre-compromise detection capabilities—specifically Defense Evasion and Persistence—over post-compromise impact analysis, though the modular skill structure allows for future expansion into these areas.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →