MITRE ATT&CK coverage

Every technique QPen can express, and which of them have been triggered by an engagement so far. A technique lights up when a finding or a red team action in its category has landed at least once.

8 / 8
Techniques triggered
Across every engagement
4
Tactics represented
Credential Access, Discovery, Initial Access, Reconnaissance
3
Finding categories
Each maps to a technique set

Technique coverage

T1040
Network Sniffing
Credential Access
Triggered in 4 engagements

Establish sessions with a hybrid group so a recorded transcript cannot be unwound once quantum capability arrives.

T1046
Network Service Discovery
Discovery
Triggered in 3 engagements

Restrict management listeners to an allow listed source range and retire services that carry no current owner.

T1133
External Remote Services
Initial Access
Triggered in 1 engagement

Terminate remote desktop and remote framebuffer access inside a quantum safe tunnel rather than on the public interface.

T1190
Exploit Public Facing Application
Initial Access
Triggered in 4 engagements

Remove unauthenticated administrative paths from the public origin and place a policy aware proxy in front of it.

T1539
Steal Web Session Cookie
Credential Access
Triggered in 4 engagements

Set Secure, HttpOnly and SameSite on every session cookie and scope the cookie to the narrowest path that works.

T1552
Unsecured Credentials
Credential Access
Triggered in 1 engagement

Move credential material into a hardware backed store, rotate on exposure and require a second factor on every administrative login.

T1557
Adversary in the Middle
Credential Access
Triggered in 4 engagements

Pin the issuing authority and require hybrid key agreement so an interposed relay cannot substitute its own public key.

T1592
Gather Victim Host Information
Reconnaissance
Triggered in 3 engagements

Suppress server, framework and build version banners at the edge so reconnaissance yields no version specific target list.

Category to technique map

A finding carries a category, and the category resolves to the techniques that category can express. The scanner uses the same map the Rust engine does.

CategoryTechniques
Web T1190 T1592 T1539 T1557
Network T1046 T1133
Cryptography T1040 T1557

Where each technique was seen

TechniqueTacticEngagementsTargets
T1040 Network Sniffing Credential Access 4 payments.firstnationalbank.com, api.firstnationalbank.com, treasury.firstnationalbank.com, branches.firstnationalbank.com
T1046 Network Service Discovery Discovery 3 payments.firstnationalbank.com, 192.168.10.45, branches.firstnationalbank.com
T1133 External Remote Services Initial Access 1 192.168.10.45
T1190 Exploit Public Facing Application Initial Access 4 payments.firstnationalbank.com, admin.firstnationalbank.com, treasury.firstnationalbank.com, branches.firstnationalbank.com
T1539 Steal Web Session Cookie Credential Access 4 payments.firstnationalbank.com, admin.firstnationalbank.com, treasury.firstnationalbank.com, branches.firstnationalbank.com
T1552 Unsecured Credentials Credential Access 1 treasury.firstnationalbank.com
T1557 Adversary in the Middle Credential Access 4 payments.firstnationalbank.com, admin.firstnationalbank.com, treasury.firstnationalbank.com, branches.firstnationalbank.com
T1592 Gather Victim Host Information Reconnaissance 3 admin.firstnationalbank.com, treasury.firstnationalbank.com, branches.firstnationalbank.com