Generate MITRE ATT&CK and D3FEND from a list of CVEs. Database with CVE, CWE, CAPEC, MITRE ATT&CK D3FEND and ATLAS Techniques data is updated daily. Showcased at BlackHat Europe 2025 Arsenal.
-
Updated
Sep 28, 2026 - Python
Generate MITRE ATT&CK and D3FEND from a list of CVEs. Database with CVE, CWE, CAPEC, MITRE ATT&CK D3FEND and ATLAS Techniques data is updated daily. Showcased at BlackHat Europe 2025 Arsenal.
OWASP Python framework for automated STRIDE threat modeling as code — MITRE ATT&CK mapping, D3FEND mitigations, Attack Flow, CAPEC, severity scoring, SVG/HTML reports & MITRE Navigator layers. DevSecOps & CI/CD ready.
An open, threat-informed cybersecurity reference library — 140 in-depth references, 16 how-to guides, and 47 discipline paths, anchored to MITRE ATT&CK and mapped to real controls, detections, and tooling. Free & MIT-licensed.
My PhD thesis in Computer Science and related resources: "An Ontological Approach to Security Modeling" (Free University of Bozen-Bolzano)
Project Raven D3FEND Defender Edition — CDP-grounded, D3FEND OWL v1.0 canonical, defender-only. Engineering package for OpenAI Cybersecurity Grant submission.
An Ontological Analysis and Redesign of the D3FEND Cybersecurity Model
754 structured cybersecurity skills for AI agents. Mapped to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF. Works with Claude Code, GitHub Copilot, Codex, Cursor, Gemini and 20+ platforms. Apache 2.0.
Security Knowledge Graph Triples
Defensive, local Burp Suite extension mapping existing findings to CWE, OWASP Web/API/Mobile/MASVS/ASVS/GenAI, MITRE ATT&CK/D3FEND/ATLAS/AADAPT/F3 and CVSS 4.0, with explainable confidence and local JSON/CSV/Markdown/SARIF exports.
Portable SecOps content, structure and metrics above open standards (CACAO v2, Sigma, OSCAL, D3FEND, OCSF), compiled to n8n, Temporal or LangGraph. A Digital Commons for sovereign security operations in the EU.
Correlates every NVD CVE with CWE, CAPEC, ATT&CK, D3FEND, OWASP, CISA KEV, Vulnrichment SSVC, and EPSS, with APT links only where MITRE ATT&CK cites the CVE. Search-first web app, MCP server, daily fail-closed updates via GitHub Actions.
Behavioural anomaly detection on AWS CloudTrail with a human-gated SOAR containment playbook. Per-principal IAM baselines in DynamoDB, six-step Step Functions response, mapped to ATT&CK for Cloud and D3FEND. All Terraform.
Browser game for practicing MITRE ATT&CK technique mapping and D3FEND countermeasures, built on the official datasets.
A local-first home cyber hygiene audit app with D3FEND-informed defensive guidance. Part of the Blanzy Labs AI app family.
754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 26 security domains · Apache 2.0
A collection of Large Language Model (LLM) prompts helpful for various cybersecurity tasks.
A collection of tools & guides for the planning and implementation of MITRE D3FEND. This repository is independent research and is not an official nor a sanctioned MITRE D3FEND resource.
Python toolchain that maps MITRE ATT&CK techniques to D3FEND defenses and builds ATT&CK Navigator coverage layers from STIX data.
To associate your repository with the d3fend topic, visit your repo's landing page and select "manage topics."