Prologue / IoPE
The pre-existing condition and the execution authority it supplied.
ATTACK STORIES · THREAT-INFORMED DEFENSE
ATT&CK describes how adversaries operate. The Prologue reveals the authority-supplying conditions that make those behaviors possible. NIST SP 800-53 identifies where defenders can prevent, constrain, detect, or deny the conversion.
Research lineage
The MITRE Center for Threat-Informed Defense Mappings Explorer connects security controls and capabilities to adversary behavior in MITRE ATT&CK®. Attack Stories extend that bridge upstream to determine whether those controls reach the Prologue.
The pre-existing condition and the execution authority it supplied.
The behavior that consumed, inherited, enabled, or propagated the condition.
The protection capability tested against the condition—not accepted by association alone.
Where defenders can govern, prevent, constrain, detect, or deny conversion.
“Taking a threat-informed defense approach that connects defender intelligence to protection capabilities codified the notion of building security in.”
Federal Cyber Defense Specialist
“Privilege management is no longer merely an administrative IT control. It is a construct for cyber defense, as these mappings demonstrate and as the prevalence of privilege across cyberattacks in the wild makes clear.”
Kevin E. Greene
Primary references: CTID Mappings Explorer · MITRE ATT&CK · NIST SP 800-53 Rev. 5
Five-case assessment
Scores reflect how well the mapping model reaches each story’s Prologue. They do not measure compliance or claim that a control was implemented. Scores are case-specific qualitative assessments—not normalized by condition or relationship count.
Cross-story control heat map
Cells count admitted Prologue conditions with a retained control relationship. Frequency is not importance, implementation, or compliance.
IoPE → ATT&CK → NIST