
Rule-based CLI tool that grades organizational defenses against MITRE ATT&CK and D3FEND frameworks, detects security gaps, and proposes mitigations. Supports JSON/plaintext inputs, SBOM generation, and vulnerability analysis.
D3FENDer is a rule-based CLI tool developed by Michael for his thesis titled Development of a security assessment and gap detection system using the MITRE ATT&CK and D3FEND Frameworks. It is designed to evaluate an organization's existing defensive measures, identify security gaps, detect various attack vectors and propose mitigations based on the MITRE ATT&CK and D3FEND Knowledge Bases.
This project is part of an academic thesis and focuses on transparency, explainability, practical use in SOC workflows, and DevSecOps Principles.
There is an online and showcase version of D3FENDer hosted using Railway that presents its main capabilities. For more details please read the presentation presentation.pdf, or view the dedicated github repository at .
The website is hosted at https://d3fender.up.railway.app