Security Frameworks We Track
Every post mapped to industry-standard frameworks — one resource, six compliance checkboxes.
MITRE Fight Fraud Framework (F3) v1.1
MITRE's Fight Fraud Framework (F3) fills the gap ATT&CK leaves after initial compromise — covering Positioning (FA0001) and Monetization (FA0002) tactics that traditional frameworks don't enumerate. Co-developed by JPMorganChase, Citigroup, Lloyds, CrowdStrike, and FS-ISAC.
F3 addresses AI-enabled fraud at every stage: deepfake-powered account opening, synthetic identity seeding, AI-driven social engineering, automated money mule orchestration, and cryptocurrency off-ramping.
MITRE ATT&CK v19.1
The industry standard for adversary TTPs. 15 tactics, 286 techniques. Every post maps relevant techniques (T1078, T1566, T1098, etc.) with validated IDs.
View ATT&CK-tagged posts →NIST CSF 2.0
Six-function framework: Govern, Identify, Protect, Detect, Respond, Recover. Posts map to specific categories (DE.CM, PR.AA, RS.MI, etc.).
View CSF-tagged posts →MITRE ATLAS v5.4
AI/ML adversarial threat matrix. 16 tactics, 84 techniques covering prompt injection, model poisoning, data manipulation, and agent hijacking.
View ATLAS-tagged posts →MITRE D3FEND v1.3
Defensive countermeasure catalog. 7 categories, 267 techniques mapped to post-specific detection and prevention strategies.
View D3FEND-tagged posts →NIST AI RMF 1.0
AI risk management — Govern, Map, Measure, Manage. 4 functions, 72 subcategories for governing AI system risks.
View AI RMF-tagged posts →OWASP Agentic AI Top 10
Emerging standard for agent-specific threats: Tool Misuse, Excessive Agency, Privilege Compromise, and Prompt Leakage. Coverage expanding as the standard matures.
View OWASP-tagged posts →Our Coverage by Framework
We're the first independent security publication to map all content to multiple frameworks simultaneously — following the methodology proven by the 817-skill Anthropic Cybersecurity Skills library (18.8K ★). Each post carries frontmatter tags that map to the relevant framework techniques, so you can find content by the compliance standard you care about.