Capability · Enterprise

Not just what is exposed.
What it lets someone do.

A list of weaknesses is not a threat model. Every GuardianGaze finding is mapped to the MITRE ATT&CK tactic and technique it enables, so the report describes how an intrusion would proceed rather than only where the gaps are.

Observed only. Nothing is exploited or tested against your systems.

Tactics and techniques

From exposure to intrusion path

The same finding can be a footnote or a front door depending on what it enables. Mapping makes that difference explicit.

Tactic

Why an attacker would

Each finding is placed against the tactic it serves: the objective an attacker is pursuing, not just the weakness itself.

Technique

How they would do it

Findings map down to technique level, so the path from an exposure to an actual intrusion is explicit rather than implied.

Coverage

Where you are thin

Mapping findings across tactics shows which stages of an intrusion you would struggle to detect or interrupt.

Worked example

One finding, fully mapped

A deterministic domain finding, carried through to the technique it enables and the control it breaks.

FindingDMARC policy left at p=none across three sending domains
TacticInitial Access
TechniquePhishing, an unenforced policy lets mail be spoofed as your domain
EvidenceThe published DNS records that produced the finding
ComplianceThe mapped control this breaks, across the frameworks you have enabled
RemediationThe record change required, with an SLA attached

What the mapping gives you

  • Tactic and technique on every finding, in every report
  • A view of which intrusion stages your exposures enable
  • Shared vocabulary with your detection and response team
  • A defensible answer to “so what” on any individual finding

What it does not claim

  • Nothing is exploited, findings are observed, not proven by attack
  • It is not a penetration test or a red-team engagement
  • It does not assess your internal detection coverage
  • Raw counts are not inflated to make coverage look broader
MITRE ATT&CK coverage dashboard showing tactics covered, techniques mapped and findings mapped by tactic

Coverage broken down by tactic, from reconnaissance through initial access, mapped straight from findings

Questions

Common questions

Why map outside-in findings to ATT&CK at all?

ATT&CK describes what attackers do once they are in motion. Mapping an external exposure to the tactic and technique it enables turns a list of weaknesses into a description of how an intrusion would actually proceed, which is what a security team plans against.

Does this replace a red team?

No. Nothing is exploited, every finding is observed from the public internet without touching your systems. The mapping tells you which techniques your exposures would enable; a red team tells you whether your detection and response actually hold up.

How does this show up in reports?

Each finding carries its tactic and technique alongside severity, evidence, remediation and the compliance control it breaks. The technical and executive reports both carry it, at different levels of detail.

See which techniques your exposure enables

The mapping is part of every assessment, not a separate module or an upgrade.

Free for your own organisation.