mitigations_for_technique
Find NIST 800-53r5 controls and DISA STIG mitigations for a MITRE ATT&CK technique, with optional severity or system filters.
Instructions
Return 800-53r5 controls and the DISA STIG findings that mitigate an ATT&CK technique. The answer opens with summary: rules found, rules per CAT, control_counts (how many controls map and how many have rules), cat_i (the CAT I V- ids with their count) and controls_with_rules. Use those counts rather than counting lists yourself. Then each control lists the rule ids of its findings, and findings lists each finding once. Findings carry no check or fix text: call finding_details with their rule ids or V- ids for DISA's exact steps. severity narrows findings to CAT levels, e.g. ["I"]. A technique id ATT&CK has revoked (e.g. T1562) is answered for its replacement, and the response reports the redirect in technique.redirected_from. Include the product build in system_description where one exists (e.g. 'ESXi 8.0 U3'): some products ship two STIG versions with different remediations, and the build selects the one that applies. stig_ids narrows to benchmarks you already know and accepts at most 200; to scope a system you cannot name, pass system_description instead and let the resolver do it. If the knowledge base is not built yet this returns {"status": "not_ready"} with the commands to run, rather than an error.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| severity | No | ||
| stig_ids | No | ||
| technique_id | Yes | ||
| system_description | No |