FRAMEWORK COVERAGE

Three frameworks. Three environments.

Each MITRE framework was built for a specific environment. ELDRAEN applies all three, so intelligence, assessments and platform data stay consistently mapped regardless of where the threat originates.

ENTERPRISE & ICS

MITRE ATT&CK®

The global standard for cataloguing adversary tactics, techniques and procedures. ATT&CK covers enterprise IT — Windows, macOS, Linux, cloud and containers — as well as industrial control systems. ELDRAEN maps all threat reporting and assessment findings to ATT&CK, giving clients a standardised view of adversary behaviour regardless of how the intelligence was sourced.

ATT&CK is the mapping backbone for enterprise threat intelligence, assessments and adversary profiling. Every flash alert, report and IOC in the platform is contextualised against the relevant technique. Detection rules in Sigma, KQL, YARA and SPL ship alongside mapped TTPs.

TECHNIQUE COVERAGE INCLUDES
  • Reconnaissance and resource development
  • Initial access and execution techniques
  • Persistence, privilege escalation and defence evasion
  • Credential access, discovery and lateral movement
  • Command and control, exfiltration and impact
  • Industrial control system technique coverage
DIGITAL ASSET

MITRE AADAPT®

The adversary behaviour framework for digital asset ecosystems. AADAPT fills the gap ATT&CK leaves when the target is a cryptocurrency exchange, DeFi protocol, Web3 application or custody operation. Most providers do not use AADAPT because they lack the domain depth to do it accurately. ELDRAEN has direct operational depth in digital asset security.

Digital asset threat intelligence and Web3 security assessments are mapped to AADAPT. The platform tracks threat actors, TTPs and IOCs against AADAPT identifiers, providing a consistent framework reference for an environment ATT&CK was not designed to cover.

TECHNIQUE COVERAGE INCLUDES
  • Smart contract exploitation and protocol manipulation
  • Private key theft and wallet compromise
  • DeFi bridge attacks and liquidity manipulation
  • Exchange infrastructure compromise
  • Social engineering targeting digital asset operations
  • Custody infrastructure attack techniques
AI & MACHINE LEARNING

MITRE ATLAS®

The adversarial machine learning knowledge base. ATLAS catalogues the tactics and techniques used against AI and ML systems — from adversarial inputs and model evasion to prompt injection and ML supply chain attacks. As AI adoption expands the attack surface, ATLAS provides the structure needed to discuss, assess and remediate AI-specific threats.

AI system assessments and AI-focused intelligence are mapped to ATLAS. Clients running models in production get findings tied to specific adversarial techniques, with mitigations that fit their deployment architecture.

TECHNIQUE COVERAGE INCLUDES
  • Adversarial input and model evasion techniques
  • Prompt injection and LLM-specific attack patterns
  • ML supply chain and model provenance risks
  • Data poisoning and training-time attacks
  • Model theft and extraction
  • AI-enabled adversary tradecraft

See it mapped in the platform.