techniques_for_actor
List a MITRE ATT&CK actor's techniques and optionally map them to NIST 800-53 controls and DISA STIG mitigations for specified systems.
Instructions
List an ATT&CK actor's techniques, optionally expanded with mitigations for given systems. actor is an ATT&CK group id, name or alias; case, spacing, punctuation and a trailing "Group" or "Team" are ignored, and actor.matched_as then names what matched. actor.also_matches, when present, lists other groups the same label loosely names. A misspelling is not corrected: the error names the closest groups, so call again with the group id of the one meant. The answer opens with summary, which counts the techniques; with include_mitigations it adds the same counts mitigations_for_technique gives, across every technique. Use those counts rather than counting lists yourself. controls lists each control once with its rule ids, and findings lists each finding once, without check or fix text (call finding_details for those). Each technique lists its control ids grouped by where the mapping came from ("ctid" or "override"). stig_ids accepts at most 200; it and severity (CAT levels, e.g. ["I"]) are validated always but only take effect with include_mitigations. To scope a system you cannot name, pass system_description instead. If the knowledge base is not built yet this returns {"status": "not_ready"} with the commands to run, rather than an error.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| actor | Yes | ||
| severity | No | ||
| stig_ids | No | ||
| system_description | No | ||
| include_mitigations | No |