Cover image for project: Nexus MITRE ATT&CK Compliance IN PROGRESS

Technical summary

Native NEXUS plugin that automatically checks MITRE ATT&CK mitigations in the environment, calculates a compliance score and creates tasks for failures. Checks evaluate code, configuration and plugins on the host or in CI, persist evidence and link it to NIST/ISO controls in Compliance Hub without relying on an external API.

Executed scope

  • plugin.json — v1.0.1, is_core: true, NEXUS category, lucide shield-alert icon with icon_bg #fef2f2, settings_route "plugin=nexus-mitre-attack-compliance".
  • Registrations: registerTab("nexus-mitre-attack-compliance", "MITRE ATT&CK", "shield-alert", tab.php, "NEXUS") and registerDoc(...).
  • 11 API actions (plugin.php, via PluginManager::registerApiAction) — mitre_status (plugin/version/score/stats/settings/ci), mitre_dashboard (persisted + ci_last; runs checks when empty), mitre_checks_list (catalog without running), mitre_check_run (runs + persists 1), mitre_check_all (reruns all), mitre_create_tasks (tasks for fail + optional partial), mitre_report (score markdown + table), mitre_settings_save (mitre_attack_compliance config), mitre_lookup (check_run alias for slash), mitre_import_ci (CI JSON; requires tasks.php + nexus-compliance-hub/backend.php for auto-create), mitre_ci_last.
  • Database: mitre_install() on load — CREATE TABLE IF NOT EXISTS mitre_check_results (mitigation_id PK, status, score, summary, details, evidence, task_id, source default 'host', repo, sha, checked_at) + light migration (ALTER for CI columns).
  • Catalog: 23 mitigations (M1000–M1036) with title/PT-BR description/priority; M1024 na (Windows Registry); hub_controls per mitigation (NIST CSF + ISO 27001).
  • Checks: mitre_run_check() — per-ID match inspecting code (password_hash, CSP, HSTS, CSRF, nx_secure_exec, login_attempts), PHP config (PHP_VERSION_ID, disable_functions, fileperms), active plugins (cors, groups, nexus-security-scanner, virustotal, hybrid-analysis, captcha) and artifacts (lockfiles, docs SECURITY*, CONVENTIONS.md, workflows).
  • CI: cli/mitre-ci-scan.php CLI (DB-free CI mode via mitre_set_ctx, import-ready JSON, soft-fail) + mitre-compliance job in nexus-security.yml (cache, PHP 8.2, curl upload with NEXUS_TOKEN).
  • Compliance Hub integration: mitre_push_hub_evidence() — evidence line [CI MITRE date] ID — status (repo@sha) per mapped control, without breaking the import.
  • Tasks: mitre_find_open_task() ([MITRE M####]% title in open tasks — avoids false positives) + task_create with title/markdown description/priority.
  • Intelligence Hub: mitre_intel_enrich() — \bM\d{4}\b, only catalog IDs, severity fail→high/partial→medium/pass·n_a→info, mitre_mitigation artifact.
  • Fast Responses: fastr.json — /mitre <M1027> via mitre_lookup (required mitigation_id arg, pass_task_id: false); also integrates with /ia (fast-responses) as a tool.
  • Alpine.js UI (tab.php, 381 lines): score ring with scoreColor/scoreLabel, per-status cards, header with last CI scan, filters (status, M####/title search), check cards with hub_controls chips (teal → Compliance Hub) and ?task= link, copyable report, config with toast.

Stack and tools

  • PHP 8 (no framework, strict_types)
  • MySQL 8 (mitre_check_results — DDL on load + light migration)
  • Alpine.js + Tailwind CSS
  • GitHub Actions (nexus-security.yml — mitre-compliance job with cache and upload)
  • NEXUS plugin system (PluginManager::registerTab/registerDoc/registerApiAction)
  • Intelligence Hub (nx_intel_register_enricher) + Compliance Hub (compliance_save)

Operational tags

  • MITRE
  • ATT&CK
  • Compliance
  • Security
  • Score
  • Mitigations
  • NEXUS Plugin
  • CI

Operational result

  • MITRE ATT&CK compliance score computed automatically (average per mitigation, N/A excluded) and shown in the dashboard with a ring and label.
  • 23 mitigations verified through static inspection of code/config/plugins — no external API key and no host agent.
  • Non-conformities become trackable NEXUS tasks ([MITRE M####] … — non-compliance) with open-task dedupe; the CI import also auto-creates tasks for fail.
  • GitHub Actions CI (mitre-compliance job) with cache and soft-fail: results are imported into NEXUS (source=ci) and evidence is cross-referenced with the Compliance Hub NIST/ISO controls.
  • Host runtime checks (e.g. disable_functions) report partial with a ci-runtime reason — avoiding false negatives on the runner.
  • M#### codes cited in tasks/comments get enriched in the Intelligence Hub with check status and severity.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Static and continuous security evaluation engine based on the MITRE ATT&CK framework. Performs automated checks for defensive mitigations (M1000–M1036) across source code, infrastructure configurations, and CI/CD pipelines, mapping security posture directly to NIST CSF and ISO 27001 controls.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.