Not just what is exposed.
What it lets someone do.
A list of weaknesses is not a threat model. Every GuardianGaze finding is mapped to the MITRE ATT&CK tactic and technique it enables, so the report describes how an intrusion would proceed rather than only where the gaps are.
Observed only. Nothing is exploited or tested against your systems.
From exposure to intrusion path
The same finding can be a footnote or a front door depending on what it enables. Mapping makes that difference explicit.
Why an attacker would
Each finding is placed against the tactic it serves: the objective an attacker is pursuing, not just the weakness itself.
How they would do it
Findings map down to technique level, so the path from an exposure to an actual intrusion is explicit rather than implied.
Where you are thin
Mapping findings across tactics shows which stages of an intrusion you would struggle to detect or interrupt.
One finding, fully mapped
A deterministic domain finding, carried through to the technique it enables and the control it breaks.
| Finding | DMARC policy left at p=none across three sending domains |
| Tactic | Initial Access |
| Technique | Phishing, an unenforced policy lets mail be spoofed as your domain |
| Evidence | The published DNS records that produced the finding |
| Compliance | The mapped control this breaks, across the frameworks you have enabled |
| Remediation | The record change required, with an SLA attached |
What the mapping gives you
- Tactic and technique on every finding, in every report
- A view of which intrusion stages your exposures enable
- Shared vocabulary with your detection and response team
- A defensible answer to “so what” on any individual finding
What it does not claim
- Nothing is exploited, findings are observed, not proven by attack
- It is not a penetration test or a red-team engagement
- It does not assess your internal detection coverage
- Raw counts are not inflated to make coverage look broader

Coverage broken down by tactic, from reconnaissance through initial access, mapped straight from findings
Common questions
Why map outside-in findings to ATT&CK at all?
ATT&CK describes what attackers do once they are in motion. Mapping an external exposure to the tactic and technique it enables turns a list of weaknesses into a description of how an intrusion would actually proceed, which is what a security team plans against.
Does this replace a red team?
No. Nothing is exploited, every finding is observed from the public internet without touching your systems. The mapping tells you which techniques your exposures would enable; a red team tells you whether your detection and response actually hold up.
How does this show up in reports?
Each finding carries its tactic and technique alongside severity, evidence, remediation and the compliance control it breaks. The technical and executive reports both carry it, at different levels of detail.
See which techniques your exposure enables
The mapping is part of every assessment, not a separate module or an upgrade.
Free for your own organisation.