IN PROGRESS
Technical summary
Native NEXUS plugin that automatically checks MITRE ATT&CK mitigations in the environment, calculates a compliance score and creates tasks for failures. Checks evaluate code, configuration and plugins on the host or in CI, persist evidence and link it to NIST/ISO controls in Compliance Hub without relying on an external API.
Executed scope
plugin.json— v1.0.1,is_core: true, NEXUS category, lucideshield-alerticon withicon_bg #fef2f2,settings_route "plugin=nexus-mitre-attack-compliance".- Registrations:
registerTab("nexus-mitre-attack-compliance", "MITRE ATT&CK", "shield-alert", tab.php, "NEXUS")andregisterDoc(...). - 11 API actions (
plugin.php, viaPluginManager::registerApiAction) —mitre_status(plugin/version/score/stats/settings/ci),mitre_dashboard(persisted + ci_last; runs checks when empty),mitre_checks_list(catalog without running),mitre_check_run(runs + persists 1),mitre_check_all(reruns all),mitre_create_tasks(tasks for fail + optional partial),mitre_report(score markdown + table),mitre_settings_save(mitre_attack_complianceconfig),mitre_lookup(check_run alias for slash),mitre_import_ci(CI JSON; requires tasks.php + nexus-compliance-hub/backend.php for auto-create),mitre_ci_last. - Database:
mitre_install()on load — CREATE TABLE IF NOT EXISTSmitre_check_results(mitigation_id PK, status, score, summary, details, evidence, task_id, source default 'host', repo, sha, checked_at) + light migration (ALTER for CI columns). - Catalog: 23 mitigations (M1000–M1036) with title/PT-BR description/priority; M1024
na(Windows Registry);hub_controlsper mitigation (NIST CSF + ISO 27001). - Checks:
mitre_run_check()— per-ID match inspecting code (password_hash, CSP, HSTS, CSRF, nx_secure_exec, login_attempts), PHP config (PHP_VERSION_ID, disable_functions, fileperms), active plugins (cors, groups, nexus-security-scanner, virustotal, hybrid-analysis, captcha) and artifacts (lockfiles, docs SECURITY*, CONVENTIONS.md, workflows). - CI:
cli/mitre-ci-scan.phpCLI (DB-free CI mode viamitre_set_ctx, import-ready JSON, soft-fail) +mitre-compliancejob innexus-security.yml(cache, PHP 8.2, curl upload with NEXUS_TOKEN). - Compliance Hub integration:
mitre_push_hub_evidence()— evidence line[CI MITRE date] ID — status (repo@sha)per mapped control, without breaking the import. - Tasks:
mitre_find_open_task()([MITRE M####]%title in open tasks — avoids false positives) +task_createwith title/markdown description/priority. - Intelligence Hub:
mitre_intel_enrich()—\bM\d{4}\b, only catalog IDs, severity fail→high/partial→medium/pass·n_a→info,mitre_mitigationartifact. - Fast Responses:
fastr.json—/mitre <M1027>viamitre_lookup(requiredmitigation_idarg,pass_task_id: false); also integrates with/ia(fast-responses) as a tool. - Alpine.js UI (
tab.php, 381 lines): score ring withscoreColor/scoreLabel, per-status cards, header with last CI scan, filters (status, M####/title search), check cards withhub_controlschips (teal → Compliance Hub) and?task=link, copyable report, config with toast.
Stack and tools
- PHP 8 (no framework,
strict_types) - MySQL 8 (
mitre_check_results— DDL on load + light migration) - Alpine.js + Tailwind CSS
- GitHub Actions (
nexus-security.yml—mitre-compliancejob with cache and upload) - NEXUS plugin system (
PluginManager::registerTab/registerDoc/registerApiAction) - Intelligence Hub (
nx_intel_register_enricher) + Compliance Hub (compliance_save)
Operational tags
- MITRE
- ATT&CK
- Compliance
- Security
- Score
- Mitigations
- NEXUS Plugin
- CI
Operational result
- MITRE ATT&CK compliance score computed automatically (average per mitigation, N/A excluded) and shown in the dashboard with a ring and label.
- 23 mitigations verified through static inspection of code/config/plugins — no external API key and no host agent.
- Non-conformities become trackable NEXUS tasks (
[MITRE M####] … — non-compliance) with open-task dedupe; the CI import also auto-creates tasks forfail. - GitHub Actions CI (
mitre-compliancejob) with cache and soft-fail: results are imported into NEXUS (source=ci) and evidence is cross-referenced with the Compliance Hub NIST/ISO controls. - Host runtime checks (e.g.
disable_functions) reportpartialwith aci-runtimereason — avoiding false negatives on the runner. M####codes cited in tasks/comments get enriched in the Intelligence Hub with check status and severity.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Static and continuous security evaluation engine based on the MITRE ATT&CK framework. Performs automated checks for defensive mitigations (M1000–M1036) across source code, infrastructure configurations, and CI/CD pipelines, mapping security posture directly to NIST CSF and ISO 27001 controls.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- GitHub Actions
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.