Where the defensive playbook runs out
MITRE's D3FEND catalog answers 44% of the enterprise ATT&CK matrix, and two whole attack stages have no defensive technique at all. Where the defenses cluster, and where they thin out. Last updated: 2026-08-10
MITRE keeps two catalogs that face each other. ATT&CK lists what attackers do. D3FEND lists the defensive techniques that answer them. MITRE also publishes which defense counters which attack. I brought that mapping onto our coverage map, laid it over the whole enterprise ATT&CK matrix, and looked for where the defensive side simply runs out. Two things stood out.
The two stages no defensive technique reaches
Reconnaissance and resource development sit at the front of every attack. Scanning your perimeter, harvesting employee names, registering lookalike domains, building the malware. In MITRE's own mapping, not one D3FEND technique counters any of it. Both stages score zero.
That is not an oversight. Those stages happen outside your systems, before the attacker touches anything you run. A catalog of defensive techniques can only act on what reaches your environment. So the defensive playbook starts at initial access and has nothing to say about the two steps before it. If you want to see an attacker casing you, that job belongs to threat intelligence and exposure management, not to the defensive technique catalog.
Inside the wire, the coverage is lopsided
For the twelve stages that do happen on your systems, coverage ranges from thin to strong. Here is the share of each stage's techniques that have at least one D3FEND countermeasure.
| Attack stage | Countered | Share |
|---|---|---|
| Reconnaissance | 0 / 46 | 0% |
| Resource development | 0 / 50 | 0% |
| Execution | 9 / 46 | 19% |
| Impact | 12 / 33 | 36% |
| Defense evasion | 84 / 204 | 41% |
| Discovery | 21 / 43 | 48% |
| Command and control | 24 / 41 | 58% |
| Collection | 23 / 36 | 63% |
| Lateral movement | 14 / 22 | 63% |
| Persistence | 41 / 64 | 64% |
| Initial access | 10 / 15 | 66% |
| Exfiltration | 13 / 19 | 68% |
| Credential access | 38 / 52 | 73% |
| Privilege escalation | 21 / 26 | 80% |
Countered = the technique has at least one D3FEND countermeasure in MITRE's mapping. Our ATT&CK bundle splits defense evasion into two internal buckets; they are recombined here.
The pattern is worth reading. Defenses cluster where the attacker is already inside and reaching for more: privilege escalation and credential access are the best covered, at 80% and 73%. The thin end is execution at 19% and impact at 36%. Stopping code from running, and stopping the damage once it does, are the stages the technique catalog answers least.
This mapping is MITRE's, not ours
I want to be plain about where this comes from. Every other cross-walk on this site is one we authored and graded ourselves. This one is not. D3FEND does not store a direct link from a defense to an attack. It reasons the link through a shared idea of the data each one touches, and MITRE publishes the result. I ingested that published result rather than invent my own, because inventing it would be exactly the derived mapping we tell everyone to avoid.
So on the map these edges carry their own label and are held apart from our hand-checked ones. Turn on "authoritative only" and they grey out. They are MITRE's reasoning, shown as MITRE's, not dressed up as our judgment. A later piece will grade that reasoning against a mapping we build by hand, and see how well the two agree.
How to use this
- Security leader. Treat the catalog as a map, not a checklist. Where it is thin, at execution and impact, you are leaning on detection and response, not on a named preventive technique. And nothing in it watches the two stages before an attacker arrives.
- Lean IT. The strong areas, credentials and privilege, are also the cheap wins: multi-factor, least privilege, and account hygiene are what fills them. The thin areas need eyes, not just controls.
- Researcher. The full D3FEND-to-ATT&CK mapping is on the map over the whole enterprise matrix, with the uncovered techniques shown as empty rather than hidden. The gaps are the finding.