{"uid":"cap_NgUCUrcBLs7KeQ2TyQhn3","slug":"mitre-att-ck-mapper-mcp-cc05c37d","name":"MITRE ATT&CK Mapper MCP","description":"The premier global index of 1,069 monetized MCP nodes across 205 specialized subdomains. Gasless USDC runtime settlements via x402 V2 Spec on Base L2. Save 95% token context.","url":"https://api.m2mcent.com/mitre-attck-mapper-mcp/api/process","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"payload":{"type":"string"}}},"responseSchema":{"type":"json","example":{"success":true}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.15","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.15/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.15","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.15","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_hH-rkmIywwvzw59wy9wFS","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.15","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Maps textual descriptions of adversarial behaviors, incidents, or techniques to MITRE ATT&CK framework tactics, techniques, and sub-techniques","exampleAgentPrompt":"I have this incident report describing how an attacker used spear-phishing to gain access and then moved laterally — can you map the behaviors to specific MITRE ATT&CK techniques and tactics, giving me the technique IDs?","exampleUseCases":[{"title":"CTI report annotation with ATT&CK IDs","prompt":"Take this threat intelligence report about the Lazarus Group campaign and map every adversary behavior described to its corresponding MITRE ATT&CK technique ID and tactic name."},{"title":"SOC alert triage with ATT&CK tagging","prompt":"We got a security alert saying a process spawned cmd.exe, then ran net user and scheduled a task — can you identify the MITRE ATT&CK techniques being used so we can prioritize our response?"},{"title":"Red team exercise technique mapping","prompt":"Here are my red team exercise notes describing credential dumping via LSASS memory access and lateral movement through pass-the-hash — map these to the correct ATT&CK techniques and sub-techniques so I can fill out my report."}],"resultDescription":"A mapping of the input text to one or more MITRE ATT&CK tactics, techniques, and sub-techniques, including technique IDs (e.g. T1566.001), tactic names (e.g. Initial Access), and technique names derived from the described behaviors.","failureModes":["Empty or too-vague input string returns no technique matches","Input describing non-adversarial behavior may produce irrelevant or low-confidence mappings","Very long or multi-topic inputs may produce incomplete coverage","Network timeout or payment failure returns a 402 or 5xx error"],"whenToPreferThis":"Use this endpoint when you need to automatically annotate threat intelligence, incident reports, or security findings with standardized MITRE ATT&CK identifiers. Ideal for SOC automation, CTI enrichment pipelines, red team reporting, and any workflow that needs to translate free-text attack descriptions into structured framework references without manually browsing the ATT&CK knowledge base.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T01:17:00.462Z","isFirstParty":false}