PRIVILEGE DISRUPTION

ATTACK STORIES · THREAT-INFORMED DEFENSE

From adversary behavior to protection capability.

ATT&CK describes how adversaries operate. The Prologue reveals the authority-supplying conditions that make those behaviors possible. NIST SP 800-53 identifies where defenders can prevent, constrain, detect, or deny the conversion.

Built on an established threat-informed foundation.

The MITRE Center for Threat-Informed Defense Mappings Explorer connects security controls and capabilities to adversary behavior in MITRE ATT&CK®. Attack Stories extend that bridge upstream to determine whether those controls reach the Prologue.

01

Prologue / IoPE

The pre-existing condition and the execution authority it supplied.

02

ATT&CK behavior

The behavior that consumed, inherited, enabled, or propagated the condition.

03

NIST SP 800-53

The protection capability tested against the condition—not accepted by association alone.

04

Disruption point

Where defenders can govern, prevent, constrain, detect, or deny conversion.

“Taking a threat-informed defense approach that connects defender intelligence to protection capabilities codified the notion of building security in.”

Federal Cyber Defense Specialist

“Privilege management is no longer merely an administrative IT control. It is a construct for cyber defense, as these mappings demonstrate and as the prevalence of privilege across cyberattacks in the wild makes clear.”

Kevin E. Greene

Primary references: CTID Mappings Explorer · MITRE ATT&CK · NIST SP 800-53 Rev. 5

Alignment is strong—but not uniform.

Scores reflect how well the mapping model reaches each story’s Prologue. They do not measure compliance or claim that a control was implemented. Scores are case-specific qualitative assessments—not normalized by condition or relationship count.

Which protection capabilities recur?

Cells count admitted Prologue conditions with a retained control relationship. Frequency is not importance, implementation, or compliance.

Explore the defensive path.