Cyber Resilience

Where the defensive playbook runs out

MITRE's D3FEND catalog answers 44% of the enterprise ATT&CK matrix, and two whole attack stages have no defensive technique at all. Where the defenses cluster, and where they thin out. Last updated: 2026-08-10

MITRE keeps two catalogs that face each other. ATT&CK lists what attackers do. D3FEND lists the defensive techniques that answer them. MITRE also publishes which defense counters which attack. I brought that mapping onto our coverage map, laid it over the whole enterprise ATT&CK matrix, and looked for where the defensive side simply runs out. Two things stood out.

44%of enterprise ATT&CK techniques have a D3FEND countermeasure
2whole attack stages with no defensive technique at all
271defensive techniques in the catalog

The two stages no defensive technique reaches

Reconnaissance and resource development sit at the front of every attack. Scanning your perimeter, harvesting employee names, registering lookalike domains, building the malware. In MITRE's own mapping, not one D3FEND technique counters any of it. Both stages score zero.

That is not an oversight. Those stages happen outside your systems, before the attacker touches anything you run. A catalog of defensive techniques can only act on what reaches your environment. So the defensive playbook starts at initial access and has nothing to say about the two steps before it. If you want to see an attacker casing you, that job belongs to threat intelligence and exposure management, not to the defensive technique catalog.

Inside the wire, the coverage is lopsided

For the twelve stages that do happen on your systems, coverage ranges from thin to strong. Here is the share of each stage's techniques that have at least one D3FEND countermeasure.

Attack stageCounteredShare
Reconnaissance0 / 460%
Resource development0 / 500%
Execution9 / 4619%
Impact12 / 3336%
Defense evasion84 / 20441%
Discovery21 / 4348%
Command and control24 / 4158%
Collection23 / 3663%
Lateral movement14 / 2263%
Persistence41 / 6464%
Initial access10 / 1566%
Exfiltration13 / 1968%
Credential access38 / 5273%
Privilege escalation21 / 2680%

Countered = the technique has at least one D3FEND countermeasure in MITRE's mapping. Our ATT&CK bundle splits defense evasion into two internal buckets; they are recombined here.

The pattern is worth reading. Defenses cluster where the attacker is already inside and reaching for more: privilege escalation and credential access are the best covered, at 80% and 73%. The thin end is execution at 19% and impact at 36%. Stopping code from running, and stopping the damage once it does, are the stages the technique catalog answers least.

This mapping is MITRE's, not ours

I want to be plain about where this comes from. Every other cross-walk on this site is one we authored and graded ourselves. This one is not. D3FEND does not store a direct link from a defense to an attack. It reasons the link through a shared idea of the data each one touches, and MITRE publishes the result. I ingested that published result rather than invent my own, because inventing it would be exactly the derived mapping we tell everyone to avoid.

So on the map these edges carry their own label and are held apart from our hand-checked ones. Turn on "authoritative only" and they grey out. They are MITRE's reasoning, shown as MITRE's, not dressed up as our judgment. A later piece will grade that reasoning against a mapping we build by hand, and see how well the two agree.

How to use this

See the defensive coverage on the map: /framework-map/. Pick MITRE D3FEND on the left, MITRE ATT&CK on the right.