175 mapped techniquesmax 13 frameworks per technique

COVERAGECompliance coverage map

Techniques ranked by how many compliance frameworks cite them. The top of the list is the highest-defensibility surface — buyers can trust these techniques because multiple regulations independently require coverage. Curated by Adam Lundqvist, Founder at SQUR.

Distribution

Frameworks per techniqueCountImplication
134Defensibility ceiling — buyers expect coverage
126Defensibility ceiling — buyers expect coverage
116Defensibility ceiling — buyers expect coverage
106Defensibility ceiling — buyers expect coverage
92Defensibility ceiling — buyers expect coverage
85Defensibility ceiling — buyers expect coverage
73Defensibility ceiling — buyers expect coverage
65Defensibility ceiling — buyers expect coverage
511Defensibility ceiling — buyers expect coverage
412Multi-framework backing
316Multi-framework backing
224Two frameworks cite — corroboration starts
175Single-framework only

Top 25 most-mapped techniques

TechniqueTitleFrameworksControlsFrameworks citing
T1005Data from Local System1371AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS, TIBER-EU
T1068Exploitation for Privilege Escalation1358AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS, TIBER-EU
T1190Exploit Public-Facing Application1345AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS, TIBER-EU
T1071Application Layer Protocol1341AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS, TIBER-EU
T1041Exfiltration Over C2 Channel1276AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS
T1003OS Credential Dumping1267AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS
T1078Valid Accounts1253AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS
T1027Obfuscated Files or Information1250AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP LLM, OWASP, PCI DSS, TIBER-EU
T1486Data Encrypted for Impact1242AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP LLM, OWASP, PCI DSS, TIBER-EU
T1083File and Directory Discovery1233AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS
T1021Remote Services1146CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP LLM, OWASP, PCI DSS, TIBER-EU
T1087Account Discovery1134AI Act, CIS v8, DORA, ISO 27001, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS, TIBER-EU
T1059Command and Scripting Interpreter1127AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP
T1018Remote System Discovery1120CIS v8, DORA, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS, TIBER-EU
T1547Boot or Logon Autostart Execution1119AI Act, CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP LLM, OWASP, PCI DSS, TIBER-EU
T1485Data Destruction1116AI Act, CIS v8, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS
T1133External Remote Services1033CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, PCI DSS
T1490Inhibit System Recovery1026AI Act, CIS v8, DORA, ISO 27001, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP, PCI DSS
T1071.001Web Protocols1026CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, OWASP API, OWASP LLM, OWASP
T1547.001Registry Run Keys / Startup Folder1019AI Act, CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP LLM, OWASP, PCI DSS
T1566Phishing1016AI Act, CIS v8, DORA, GDPR, ISO 27001, ISO 27701, NIS2, NIST CSF, PCI DSS, TIBER-EU
T1070.004File Deletion1015AI Act, CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP API, OWASP LLM, PCI DSS
T1046Network Service Discovery942CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP API, OWASP, PCI DSS
T1039Data from Network Shared Drive914CIS v8, DORA, GDPR, ISO 27701, NIS2, OWASP LLM, OWASP, PCI DSS, TIBER-EU
T1021.001Remote Desktop Protocol822CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP API, OWASP LLM

Showing top 25 of 175. Full distribution above. Click any technique ID to see its detail page + linked compliance edges via EdgeNeighbours.

Aggregated from 127 compliance controls across 14 frameworks. For raw cross-framework similarity see /explore/crosswalk.