CLI
mitrex — this site from the command line. 83 commands, one per endpoint, generated from the same catalogue Open APIs renders, so the two cannot disagree. Read-only, no key, no account.
Not published yet
mitrex is not on npm, so there is nothing to install today. It is a convenience wrapper over the REST API and adds no capability — every command below is a GET you can make right now with curl against https://mitre-explorer.org/api/v1. This page lists what it will do.mitrex83, one per endpointNode 22.8+ · zero runtime dependenciesread-only — every command is a GETnone — no key, no sign-up, no account, no headeraligned table in a terminal, JSON when pipedmitrex techniques T1059 mitrex groups --search lazarus mitrex cves --severity CRITICAL --limit 5 | jq '.data[].cveId' mitrex --help the resources, with examples mitrex help techniques every command for one resource, with its flags mitrex ls all 83 commands, one per line
It detects a terminal and renders a table; it detects a pipe and emits JSON, so jq works without a flag. An unknown command suggests the closest real one rather than printing all 83. Shell completion for bash, zsh and fish is generated from the same table.
ATT&CK core
Techniques, tactics, malware, mitigations, data sources, the matrix and cross-domain search.
mitrex techniquesTechnique summaries across every ATT&CK domain plus ATLAS.mitrex techniques attackIdOne technique in full — tactics, platforms, sub-techniques, groups, malware, mitigations, CAPEC, ICS assets.mitrex techniques packages attackIdPackages reachable from a technique through the CWE→CAPEC bridge.mitrex tacticsKill-chain tactics, in ATT&CK order.mitrex tactics attackIdOne tactic, every technique under it, and its ATT&CK data sources ranked by how many of those techniques each one covers.mitrex softwareMalware and tool summaries, each tagged malware or tool.mitrex software attackIdOne malware or tool — aliases, platforms, techniques used, groups, campaigns.mitrex mitigationsCountermeasure summaries.mitrex mitigations attackIdOne mitigation and every technique it addresses.mitrex data-sourcesDetection data sources and their components.mitrex data-sources attackIdOne data source — its components and the techniques they detect.mitrex matrixThe tactic × technique matrix, ready to render.mitrex relationships attackIdGraph neighbours of any ATT&CK entity, for the 360 views.mitrex entitiesEvery entity id and name in one payload — the search index the client builds Fuse.js over.mitrex proceduresProcedure examples — the free text describing how a group, malware or campaign used a technique.mitrex searchCross-domain keyword search over ATT&CK entities, OWASP categories and CSF subcategories.mitrex dashboardCorpus overview — entity counts, top groups, most-targeted techniques, ingested ATT&CK version.mitrex nav-countsHow big each part of the corpus is. Exact where cheap; CVE, IOC and advisory totals are planner estimates, named in meta.estimated.Threat actors
ATT&CK groups and campaigns, the ThaiCERT/ETDA actor set, and the sectors they target.
mitrex groupsATT&CK threat group summaries.mitrex groups attackIdOne group in full — techniques, malware, campaigns, targeted sectors, affected applications.mitrex campaignsNamed intrusion campaigns with first/last-seen dates.mitrex campaigns attackIdOne campaign — techniques, malware deployed, groups involved.mitrex external-actorsThaiCERT / ETDA actors — 500+ names beyond the ATT&CK set, with country and motivation.mitrex external-actors nameOne external actor by exact name — reference metadata only, no TTPs.mitrex sectorsIndustry sectors with the count of groups targeting each.mitrex sectors slugOne sector and the groups that target it.mitrex sectors relationships slugA sector threat landscape — groups, campaigns, malware, top techniques, vulnerable applications.CTI feeds
Reports, IOCs, Sigma rules, Atomic tests and the per-technique intelligence rollup.
mitrex feed reportsThreat-intelligence reports from OTX, Unit 42, DFIR and other RSS sources, newest first.mitrex feed reports techniques reportIdATT&CK techniques extracted from one report.mitrex feed iocsIOCs from OTX, ThreatFox, MalwareBazaar and CISA KEV, newest first.mitrex feed iocs techniques iocIdTechniques associated with one IOC, via sandbox reports.mitrex feed sigmaSigmaHQ detection rules with log source and mapped technique.mitrex feed atomicAtomic Red Team tests with executor, run command and cleanup.mitrex feed intelligence attackIdPer-technique CTI rollup — reports, IOCs, CVEs, Sigma, Atomic, D3FEND, detection strategies.mitrex feed statusIngestion health per feed — last run, row counts, errors.Vulnerabilities
CVEs with CVSS, EPSS and KEV, CAPEC patterns, and the vendor products they affect.
mitrex cvesCVE summaries with CVSS, EPSS, KEV, CWE and linked techniques — newest first, not worst first.mitrex cves cveIdOne CVE in full — CWEs, EPSS, KEV, OWASP, affected apps, GHSA alias, aliasing OSV advisories, plus techniqueLinkage saying whether its ATT&CK links are curated (CTID hand-mapped), inferred (CWE→CAPEC) or absent and why — only ~18% of CVEs carry any technique link, so an empty techniques array is the norm, not a lookup failure.mitrex cves packages cveIdOpen-source packages affected by one CVE, via its GHSA alias.mitrex applicationsAffected vendor products with CVE, technique and group counts.mitrex applications vendor productProduct 360 — CVEs, CWE profile, reachable techniques and threat groups.mitrex capecCAPEC attack-pattern summaries with CWE refs and mapped technique counts.mitrex capec idOne CAPEC pattern — prerequisites, skills, consequences, CWEs, techniques, mitigations.mitrex home recent-affectedApplications and packages hit by a new advisory recently. Refreshed daily.Supply chain
GHSA + OSV advisories, packages and per-ecosystem dashboards.
mitrex advisoriesUnified GHSA + OSV advisory rows, each tagged with its source. Severity-ranked, then newest.mitrex ghsaGHSA-only rows, with technique counts and withdrawal status the unified view omits.mitrex ghsa ghsaIdOne GitHub Security Advisory — CVSS v3 and v4, CWEs, affected packages with vulnerable and fixed ranges.mitrex osv osvIdOne OSV advisory by native id (DSA-, USN-, RLSA-, ALAS-) — distro, kernel and OS ecosystems.mitrex packagesPackage rows with advisory counts, severities and technique counts.mitrex packages ecosystem nameOne package — every advisory affecting it, with ranges where the ecosystem models them.mitrex ecosystemsPer-ecosystem advisory dashboards — totals, 14-day counts, severity split, top packages.mitrex ecosystems slugOne ecosystem in detail.Frameworks
OWASP, NIST CSF and 800-53, ISO 27001, D3FEND, Engage, RE&CT, VERIS and cloud controls.
mitrex frameworks owaspOWASP Top 10 categories for Web 2021, ML 2023 and LLM 2025, with per-category counts.mitrex frameworks owasp categoryIdOne OWASP category — CWEs, techniques, ATLAS, top CVEs, affected applications.mitrex frameworks owasp packages categoryIdPackages whose advisories carry a CWE in one OWASP category.mitrex frameworks csfNIST CSF v2 functions and subcategories with technique counts.mitrex frameworks csf subcategoryIdOne CSF v2 subcategory, with its CRI Profile crosswalk.mitrex frameworks csf techniques subcategoryIdTechniques mapped to one CSF v2 subcategory.mitrex frameworks nistNIST 800-53 r5 controls.mitrex frameworks nist techniques controlIdTechniques one 800-53 control mitigates.mitrex frameworks iso27001ISO/IEC 27001:2022 Annex A controls and clauses, reached via the CSF v2 crosswalk.mitrex frameworks d3fendD3FEND countermeasures grouped by defensive tactic.mitrex frameworks d3fend d3fendIdOne countermeasure — every technique it counters, plus overlapping countermeasures.mitrex frameworks engageMITRE Engage adversary-engagement activities by goal and approach.mitrex frameworks engage techniques engageIdTechniques one Engage activity applies to.mitrex frameworks reactRE&CT incident-response actions by response stage.mitrex frameworks verisVERIS enumerations (the Verizon DBIR taxonomy) mapped to techniques.mitrex frameworks cloud-controlsAWS, Azure and GCP security controls mapped to techniques.mitrex frameworks detectionATT&CK Detection Strategies and Analytics.mitrex frameworks technique attackIdEvery direct control mapping for one technique — 800-53, CSF, Engage, VERIS, cloud, OWASP.mitrex frameworks by-techniquesFramework coverage for a set of techniques at once — the bulk form of the route above.mitrex frameworks statusPer-framework ingest state — row counts and last sync.Compliance
Regulatory regimes bridged to ATT&CK through the Secure Controls Framework.
mitrex frameworks scfThe Secure Controls Framework catalogue — 1,534 controls, the spine every compliance framework here is crosswalked through.mitrex compliance frameworksRegulatory frameworks bridged to ATT&CK through the SCF, with coverage counts.mitrex compliance frameworks keyOne framework — every technique it references, grouped by article, with the citing ref_id.mitrex compliance techniques attackIdWhich frameworks reference one technique, with per-framework control counts.mitrex compliance tactics attackIdFramework coverage rolled up over one tactic.mitrex compliance groups attackIdFramework coverage of the techniques one threat group uses.mitrex compliance software attackIdFramework coverage of the techniques one malware or tool uses.mitrex compliance sectors slugFramework coverage of the techniques aimed at one sector.ICS / OT
ATT&CK for ICS assets and the Purdue model they are placed on.
mitrex assetsATT&CK for ICS assets — PLCs, RTUs, HMIs, historians, safety controllers, field I/O.mitrex assets attackIdOne ICS asset — ICS techniques targeting it, D3FEND countermeasures, Purdue placement.mitrex frameworks purdueThe Purdue model as data — seven levels, placed assets, and the 42-pair flow matrix.Threat profile
The ranked briefing the /profile page renders, as data.
mitrex profileThe ranked threat briefing — techniques, actors and controls scored for a stated environment.Positional arguments are shown by name — mitrex techniques attackId means mitrex techniques T1059. Flags mirror each endpoint’s query parameters; Open APIs → documents them per endpoint, with a Run button for each.