Skip to content

Frameworks

The part of the map your tools cannot see.

MITRE ATT&CK and the NIST Cybersecurity Framework give defenders, auditors, and boards a shared map of adversary behavior and defensive obligation. Most security tooling covers the right side of that map, inside the victim's network. Mythic covers the left side: the tactics an adversary executes on their own ground, before and during the breach.

01MITRE ATT&CK

Coverage where the matrix goes dark.

Most of the ATT&CK matrix is written from inside the victim's network, and that is where most detection operates. The earliest tactic columns describe what the adversary does on infrastructure they control, which is exactly what endpoint and network tooling cannot observe. Those columns are where Mythic's collection begins.

TA0043

Reconnaissance

T1590 · T1598

Before a campaign launches, actors gather victim network information and phish for access. Mythic tracks the actors doing the gathering, so targeting is visible while it is still preparation.

TA0042

Resource Development

T1583 · T1584 · T1608

Acquiring domains, compromising infrastructure, staging capabilities. This is the tactic column no product inside your network can observe, and it is where Mythic lives: watching adversary infrastructure as it is registered, stood up, and armed.

TA0011

Command and Control

T1071 · T1568

When victim networks begin talking to tracked infrastructure over application layer protocols or dynamically resolved domains, Mythic observes the exchange directly, from the infrastructure side.

TA0010

Exfiltration

T1041 · T1048

Exfiltration over the C2 channel is not inferred from volume anomalies. Mythic records the observed exchange, including what was taken, from which machine, and when.

02NIST CSF 2.0

Independent evidence for four of the six functions.

The Cybersecurity Framework organizes a security program into six functions. Mythic is not a control set and does not replace one. What it contributes is something a framework assessment values and internal tooling cannot produce: evidence gathered outside the organization, from the adversary's side of the exchange.

GOVERN

GV.OC · GV.RM · GV.SC

Boards and risk committees need external, independent input to oversee cyber risk, and CSF 2.0 makes supply chain risk management a governance obligation. Mythic gives both an evidence stream that does not depend on the instrumentation, or the candor, of the organizations being overseen, your own suppliers included.

IDENTIFY

ID.RA

Risk assessment informed by live adversary targeting rather than vulnerability inventories alone: which actors are building toward you, and which of your suppliers are already in contact with their infrastructure.

DETECT

DE.CM · DE.AE

CSF 2.0 asks for continuous monitoring and adverse event analysis. Mythic extends both beyond the perimeter, adding a monitoring plane your internal telemetry cannot reach and adverse events confirmed by observation rather than correlation.

RESPOND

RS.MA · RS.AN · RS.CO

Incident analysis with timestamped, empirical evidence of what was reached and what was taken, and incident reporting support when the determination carries a regulatory clock, including SEC cyber disclosure.

PROTECT and RECOVER remain the province of your internal controls and continuity planning. Mythic complements them; it does not claim them.

03Compliance regimes

Evidence for the clocks your regulators run.

Beyond the SEC's four-day disclosure rule, most regulated industries carry their own breach clocks and their own evidentiary burdens. Each one ultimately asks the same two questions: what happened, and when did you know. Mythic exists to answer both with observation rather than estimate.

ISO/IEC 27001:2022

A.5.7 · A.5.25 · A.5.26 · A.8.16

Threat intelligence and monitoring

The 2022 revision added A.5.7, a control that requires organizations to collect and analyze threat intelligence and act on it. Mythic satisfies the spirit of that control at its strongest: intelligence specific to your organization, drawn from adversary infrastructure, feeding the event assessment and incident response controls beside it.

HIPAA

45 CFR 164.308 · 164.400 et seq.

Security and breach notification rules

The breach notification rule turns on a risk assessment: whether there is a low probability that protected health information was compromised. Mythic replaces conjecture in that assessment with observation, showing whether data actually moved to adversary infrastructure, what moved, and when the exchange occurred.

GDPR

Articles 33 · 34

72-hour supervisory notification

Controllers must notify their supervisory authority within 72 hours of becoming aware of a personal data breach, and affected individuals when risk is high. The clock and the risk determination both depend on knowing what happened. Empirical evidence of exfiltration compresses days of forensic uncertainty into an answer.

NIS2 / DORA

Early warning 24h · Notification 72h

EU operational resilience

Essential entities under NIS2 owe an early warning within 24 hours; financial entities under DORA must classify and report major ICT incidents on similarly short timelines. Mythic gives European security and compliance teams the earliest possible awareness, often before internal detection, and the evidence to classify severity quickly.

NYDFS

23 NYCRR 500

Cybersecurity event notice

Covered financial institutions must notify the New York Department of Financial Services within 72 hours of a qualifying cybersecurity event. Confirmed, timestamped breach intelligence determines whether the threshold is met and documents the basis for the answer either way.

Mythic informs and accelerates these obligations; the legal determinations they require remain with your counsel and compliance teams.

04In practice

When the assessor asks the hard question.

Framework conversations turn difficult at a predictable moment: when an assessor, underwriter, or acquirer asks how continuous monitoring extends beyond the perimeter, or what independent evidence supports an incident timeline. Internal telemetry answers with logs the organization generated about itself. Mythic answers with observation from the other side of the exchange.

That distinction matters most when the framework language meets a clock or a signature: a materiality determination on a four-day disclosure timeline, an insurance application warranty, a representation in a purchase agreement. In each case the question is not whether a control exists, but whether the organization can demonstrate what actually happened. Empirical, timestamped, third-party observation is the strongest form that demonstration takes.

See your framework posture from the attacker's side.

MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. NIST and the Cybersecurity Framework are the work of the National Institute of Standards and Technology. Neither organization endorses Vigilocity; the mappings above describe where Mythic's intelligence applies within each framework's structure.