# Where to Find MITRE ATT&CK Coverage Details in the Anthropic Cybersecurity Skills Repository

> Discover MITRE ATT&CK coverage details in the Anthropic Cybersecurity Skills repository. Find tactical overviews and gap analysis matrices in markdown files.

- Repository: [Mahipal/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills)
- Tags: getting-started
- Published: 2026-05-24

---

**The `mukul975/Anthropic-Cybersecurity-Skills` repository stores MITRE ATT&CK coverage details in two primary markdown files: [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md) (root directory) for high-level tactical overviews and [`mappings/mitre-attack/coverage-summary.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/mappings/mitre-attack/coverage-summary.md) for detailed gap analysis matrices.**

The Anthropic Cybersecurity Skills repository maps over 750 hands-on skills to the MITRE ATT&CK framework. If you need to find MITRE ATT&CK coverage details, the project maintains dedicated documentation that specifies exactly which tactics and techniques are addressed by each skill, including visual badges and quantitative coverage statistics.

## High-Level Coverage Documentation

The repository organizes its framework alignment across two primary files, supported by detailed methodology guides.

### ATTACK_COVERAGE.md (Root Level)

Located at the repository root, **[`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md)** provides a comprehensive list of all **291 unique techniques** covered across **149 parent techniques**. This file groups entries by **tactic**—such as Execution, Persistence, Defense Evasion, and Exfiltration—and includes badge visualizations for quick scannability of coverage density.

### mappings/mitre-attack/coverage-summary.md

For granular analysis, **[`mappings/mitre-attack/coverage-summary.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/mappings/mitre-attack/coverage-summary.md)** contains a detailed matrix breaking down coverage by **tactic**, **sub-domain**, and specific **technique**. According to the repository source code, this file identifies specific gaps where additional skills would improve ATT&CK coverage completeness.

### Supporting Documentation

- **[`mappings/mitre-attack/README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/mappings/mitre-attack/README.md)**: Explains the mapping generation methodology and provides guidance on interpreting the tactic-technique tables.
- **[`mappings/README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/mappings/README.md)**: Offers a comprehensive overview of all framework mappings in the repository, including MITRE ATT&CK, NIST CSF, and OWASP alignments.

## Programmatic Access to Coverage Data

You can extract MITRE ATT&CK coverage details directly from the raw markdown files using standard data processing tools without cloning the repository.

### Extracting Data with Python

Load the coverage summary table into a pandas DataFrame for analysis:

```python
import pandas as pd
import requests
import io

url = ("https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/"
       "main/mappings/mitre-attack/coverage-summary.md")
md_text = requests.get(url).text

# The markdown table starts after the header line "---"

table_md = md_text.split("## Subdomain-to-Tactic Heat Map")[1]

df = pd.read_table(io.StringIO(table_md), sep="|", engine="python", skiprows=1)
print(df.head())

```

### Filtering Techniques via Command Line

Extract specific technique IDs for a given tactic (e.g., Execution) using standard Unix utilities:

```bash
curl -s https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/main/ATTACK_COVERAGE.md \
| awk '/## ⚡ Execution/,/##/' | grep "\[T" | sed -E 's/.*\[(T[0-9]+)\].*/\1/'

```

## Summary

- **Primary coverage file**: Root-level [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md) catalogs 291 unique techniques grouped by tactic with visual badge indicators.
- **Detailed matrix**: [`mappings/mitre-attack/coverage-summary.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/mappings/mitre-attack/coverage-summary.md) provides the tactic-technique breakdown and identifies coverage gaps across sub-domains.
- **Documentation**: README files in `mappings/mitre-attack/` explain the mapping methodology and table interpretation standards.
- **Coverage scope**: The repository maps over 750 skills to 149 parent ATT&CK techniques.
- **Machine-readable**: Raw markdown files support direct programmatic extraction via Python (pandas) or shell tools (curl/awk/sed).

## Frequently Asked Questions

### How many MITRE ATT&CK techniques does the repository cover?

The repository covers **291 unique techniques** across **149 parent techniques** in the MITRE ATT&CK framework. This comprehensive mapping connects over 750 individual cybersecurity skills to specific adversarial behaviors as documented in [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md).

### What is the difference between ATTACK_COVERAGE.md and coverage-summary.md?

[`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md) provides a high-level tactical overview organized by ATT&CK tactics with badge visualizations for quick assessment, while [`mappings/mitre-attack/coverage-summary.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/mappings/mitre-attack/coverage-summary.md) offers a detailed matrix view that breaks down coverage by sub-domain and identifies specific gaps where the skill library could expand.

### Can I export the coverage data to use in my own security tools?

Yes. Both markdown files are accessible via direct raw GitHub URLs. You can parse [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md) using regex for technique IDs, or load the structured tables from [`coverage-summary.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/coverage-summary.md) into pandas DataFrames using standard markdown parsing libraries as shown in the Python example above.

### Where can I find documentation on how the mappings were created?

The **[`mappings/mitre-attack/README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/mappings/mitre-attack/README.md)** file explains the methodology used to align skills with ATT&CK techniques. For a broader architectural view of all framework mappings (including NIST CSF and OWASP), consult **[`mappings/README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/mappings/README.md)** in the parent directory.