Where to Find MITRE ATT&CK Coverage Details in the Anthropic Cybersecurity Skills Repository
The mukul975/Anthropic-Cybersecurity-Skills repository stores MITRE ATT&CK coverage details in two primary markdown files: ATTACK_COVERAGE.md (root directory) for high-level tactical overviews and mappings/mitre-attack/coverage-summary.md for detailed gap analysis matrices.
The Anthropic Cybersecurity Skills repository maps over 750 hands-on skills to the MITRE ATT&CK framework. If you need to find MITRE ATT&CK coverage details, the project maintains dedicated documentation that specifies exactly which tactics and techniques are addressed by each skill, including visual badges and quantitative coverage statistics.
High-Level Coverage Documentation
The repository organizes its framework alignment across two primary files, supported by detailed methodology guides.
ATTACK_COVERAGE.md (Root Level)
Located at the repository root, ATTACK_COVERAGE.md provides a comprehensive list of all 291 unique techniques covered across 149 parent techniques. This file groups entries by tactic—such as Execution, Persistence, Defense Evasion, and Exfiltration—and includes badge visualizations for quick scannability of coverage density.
mappings/mitre-attack/coverage-summary.md
For granular analysis, mappings/mitre-attack/coverage-summary.md contains a detailed matrix breaking down coverage by tactic, sub-domain, and specific technique. According to the repository source code, this file identifies specific gaps where additional skills would improve ATT&CK coverage completeness.
Supporting Documentation
mappings/mitre-attack/README.md: Explains the mapping generation methodology and provides guidance on interpreting the tactic-technique tables.mappings/README.md: Offers a comprehensive overview of all framework mappings in the repository, including MITRE ATT&CK, NIST CSF, and OWASP alignments.
Programmatic Access to Coverage Data
You can extract MITRE ATT&CK coverage details directly from the raw markdown files using standard data processing tools without cloning the repository.
Extracting Data with Python
Load the coverage summary table into a pandas DataFrame for analysis:
import pandas as pd
import requests
import io
url = ("https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/"
"main/mappings/mitre-attack/coverage-summary.md")
md_text = requests.get(url).text
# The markdown table starts after the header line "---"
table_md = md_text.split("## Subdomain-to-Tactic Heat Map")[1]
df = pd.read_table(io.StringIO(table_md), sep="|", engine="python", skiprows=1)
print(df.head())
Filtering Techniques via Command Line
Extract specific technique IDs for a given tactic (e.g., Execution) using standard Unix utilities:
curl -s https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/main/ATTACK_COVERAGE.md \
| awk '/## ⚡ Execution/,/##/' | grep "\[T" | sed -E 's/.*\[(T[0-9]+)\].*/\1/'
Summary
- Primary coverage file: Root-level
ATTACK_COVERAGE.mdcatalogs 291 unique techniques grouped by tactic with visual badge indicators. - Detailed matrix:
mappings/mitre-attack/coverage-summary.mdprovides the tactic-technique breakdown and identifies coverage gaps across sub-domains. - Documentation: README files in
mappings/mitre-attack/explain the mapping methodology and table interpretation standards. - Coverage scope: The repository maps over 750 skills to 149 parent ATT&CK techniques.
- Machine-readable: Raw markdown files support direct programmatic extraction via Python (pandas) or shell tools (curl/awk/sed).
Frequently Asked Questions
How many MITRE ATT&CK techniques does the repository cover?
The repository covers 291 unique techniques across 149 parent techniques in the MITRE ATT&CK framework. This comprehensive mapping connects over 750 individual cybersecurity skills to specific adversarial behaviors as documented in ATTACK_COVERAGE.md.
What is the difference between ATTACK_COVERAGE.md and coverage-summary.md?
ATTACK_COVERAGE.md provides a high-level tactical overview organized by ATT&CK tactics with badge visualizations for quick assessment, while mappings/mitre-attack/coverage-summary.md offers a detailed matrix view that breaks down coverage by sub-domain and identifies specific gaps where the skill library could expand.
Can I export the coverage data to use in my own security tools?
Yes. Both markdown files are accessible via direct raw GitHub URLs. You can parse ATTACK_COVERAGE.md using regex for technique IDs, or load the structured tables from coverage-summary.md into pandas DataFrames using standard markdown parsing libraries as shown in the Python example above.
Where can I find documentation on how the mappings were created?
The mappings/mitre-attack/README.md file explains the methodology used to align skills with ATT&CK techniques. For a broader architectural view of all framework mappings (including NIST CSF and OWASP), consult mappings/README.md in the parent directory.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →