What problem does it solve?
Security operations centers can articulate attacker behavior at MITRE ATT&CK/ATLAS technique-level granularity, but most cannot map their own deployed defenses to the same grain, leading to under-defended systems, compliance theater, and false confidence in security postures against modern AI and cyber threats.
Core Features & Use Cases
- Offensive-to-Defensive Mapping: Converts offensive findings (CVEs, ATLAS/ATT&CK TTPs, framework control gaps, CWEs, DLP concerns) into explicit MITRE D3FEND defensive countermeasure maps.
- Layered Defense Enforcement: Every output is threaded through defense-in-depth, least-privilege, and zero-trust principles, surfacing gaps where only a single defensive layer is deployed.
- Compliance Gap Identification: Flags where common compliance frameworks (NIST, ISO 27001, NIS2, etc.) operate at too coarse a grain to address technique-level threats, eliminating audit false positives and compliance theater.
- Use Case: A blue team responding to a kernel local privilege escalation CVE can use this skill to generate a full multi-layer defensive map instead of only claiming generic EDR detection coverage, identifying missing hardening, isolation, and restore controls.
Quick Start
Use the defensive-countermeasure-mapping skill to generate a layered D3FEND defensive map for the CVE-2026-31431 kernel LPE finding, including defense-in-depth layers, least-privilege scoping, and zero-trust posture for each recommended countermeasure.