CIS Controls for Threat Mitigation
Explore how CIS Safeguards map to MITRE ATT&CK techniques to assess defensive coverage, identify gaps, and support threat-informed security …
By Suneel Sundar • February 9, 2026
MITRE ATLAS™ analyzed OpenClaw incidents that showcase how AI-first ecosystems introduce new exploit execution paths. OpenClaw is unique because it can independently make decisions, take actions, and complete tasks without continuous human oversight.
By mapping the patterns and behaviors to ATLAS Tactics, Techniques, and Procedures (TTPs) and visualizing the attack flow, the team deduced chokepoint techniques that adversaries rely on. See the Investigation Report here:
Incident ReportCTID is grateful for the contributions of our Secure AI Project Lead and CTID Research team members.
MITRE’s Center for Threat Informed Defense welcomes collaboration from the entire AI security community to inform defenders of threats introduced by open-source agentic systems like OpenClaw. Join MITRE and industry researchers to grow the ATLAS matrix and develop community tools, resources, and guidance.
© 2026 The MITRE Corporation. Approved for Public Release. ALL RIGHTS RESERVED. Document number
25-02691-4.
Explore how CIS Safeguards map to MITRE ATT&CK techniques to assess defensive coverage, identify gaps, and support threat-informed security …
A case study of 144 Sigma analytics using Windows Security log sources shows why ATT&CK mappings alone do not reveal the depth or quality of …
Summiting the Pyramid introduces implementation coverage and detection quality to help defenders measure the depth and effectiveness of detection …