Skip to main content
Labshock
LoginStart Free
← All Updates
RELEASESeptember 8, 2026

MITRE ATT&CK and D3FEND, as a Map You Walk

A technique should not stay an ID in a spreadsheet. When one appears in a guide, you can now run it on a live industrial system and see for yourself what it looks like from both sides.

MITRE ATT&CK and D3FEND are shipping into Labshock.

Not as a matrix to fill in. As a map to follow.

Where Matrix Work Usually Stops

MITRE is good at showing what an attacker can do — discovery, lateral movement, inhibit response function, impair process control, impact.

The usual workflow is familiar. Find the technique. Map it to your environment. Map controls against it.

And often the work stops there. The matrix is complete, the controls are listed, the report is ready.

But did anybody actually do it?

What We Added

When a technique appears in a guide, you can now connect it to what you are doing in the lab:

  • send the command
  • capture the traffic
  • change the process
  • build the firewall rule
  • create the detection
  • read the logs

There is no automatic green checkbox. You run it, and you see the result yourself.

Tactic, Technique, Lab, Action, Observation

That chain is the point.

You learn what a technique means. Then you see how it looks on a running industrial system — which is usually less dramatic and more specific than the name suggests.

From the defender's side you see what your controls can actually observe or stop, which is a different question from whether they are deployed.

A green cell then describes something you did, not something you claimed.

If you are checking your own mapping, note that several ICS technique IDs were revoked recently: labshocksecurity.com/news/attack-for-ics-v19-sub-techniques-revoked-ids

Try It Yourself

  • Pick one technique you currently claim coverage for and run it in a lab.
  • Check what your detection saw. If nothing, that is the finding.
  • Then do the D3FEND half — build the control and prove it changes the outcome.
  • Start free: github.com/zakharb/labshock · discord.gg/bpmaQFfW76
LABSHOCK SECURITY — OT SECURITY MUST BE TESTABLE, NOT DOCUMENTED