{
    "$schema": "cispar-mitre-map-v1",
    "description": "Mapping de técnicas ATT&CK Enterprise → detecciones de CISPAR → playbooks",
    "matrix": "enterprise",
    "tactics": [
        {
            "id": "TA0001",
            "name": "Initial Access",
            "techniques": [
                {
                    "id": "T1190",
                    "name": "Exploit Public-Facing Application",
                    "detection": {
                        "command": "ss -tlnp",
                        "indicators": [
                            "unexpected listening ports",
                            "web server on non-standard port"
                        ],
                        "log_source": "ss, nmap, /var/log/auth.log"
                    },
                    "playbook": "unauthorized-access.json",
                    "cispar_schema": "skills/cispar-network/schemas/scan_ports.json"
                },
                {
                    "id": "T1133",
                    "name": "External Remote Services",
                    "detection": {
                        "command": "ss -tnp state established | grep -v 127.0.0.1",
                        "indicators": [
                            "SSH from unknown IP",
                            "RDP connection",
                            "VPN from unusual geo"
                        ],
                        "log_source": "/var/log/auth.log, ss, last -i"
                    },
                    "playbook": "unauthorized-access.json",
                    "cispar_schema": "skills/cispar-l1-triage/schemas/monitor_system.json"
                }
            ]
        },
        {
            "id": "TA0003",
            "name": "Persistence",
            "techniques": [
                {
                    "id": "T1053",
                    "name": "Scheduled Task/Job",
                    "detection": {
                        "command": "crontab -l 2>/dev/null; ls -la /etc/cron.d/ /etc/cron.daily/ 2>/dev/null; systemctl list-timers",
                        "indicators": [
                            "new cron entry",
                            "unknown systemd timer",
                            "at job from non-root"
                        ],
                        "log_source": "crontab, systemctl, /var/log/syslog"
                    },
                    "playbook": "malware-detected.json",
                    "cispar_schema": "skills/cispar-l2-respond/schemas/investigate.json"
                },
                {
                    "id": "T1136",
                    "name": "Create Account",
                    "detection": {
                        "command": "lastlog | grep -v 'Never' ; awk -F: '$3 >= 1000 {print $1}' /etc/passwd",
                        "indicators": [
                            "new user account",
                            "UID >= 1000 not recognized"
                        ],
                        "log_source": "/etc/passwd, lastlog, /var/log/auth.log"
                    },
                    "playbook": "unauthorized-access.json",
                    "cispar_schema": "skills/cispar-l2-respond/schemas/collect_evidence.json"
                }
            ]
        },
        {
            "id": "TA0004",
            "name": "Privilege Escalation",
            "techniques": [
                {
                    "id": "T1548",
                    "name": "Abuse Elevation Control Mechanism",
                    "detection": {
                        "command": "find / -perm -4000 -type f 2>/dev/null; sudo -l 2>/dev/null",
                        "indicators": [
                            "SUID on unusual binary",
                            "sudo NOPASSWD for non-admin"
                        ],
                        "log_source": "find, sudo -l, /var/log/auth.log"
                    },
                    "playbook": "privilege-escalation.json",
                    "cispar_schema": "skills/cispar-l3-hunt/schemas/threat_hunt.json"
                }
            ]
        },
        {
            "id": "TA0006",
            "name": "Credential Access",
            "techniques": [
                {
                    "id": "T1110",
                    "name": "Brute Force",
                    "detection": {
                        "command": "grep 'Failed password' /var/log/auth.log | tail -50; lastb | head -20",
                        "indicators": [
                            "5+ failed logins from same IP in 1 min",
                            "multiple users attempted"
                        ],
                        "log_source": "/var/log/auth.log, lastb, journalctl -u sshd"
                    },
                    "playbook": "brute-force.json",
                    "cispar_schema": "skills/cispar-l1-triage/schemas/classify_event.json"
                }
            ]
        },
        {
            "id": "TA0007",
            "name": "Discovery",
            "techniques": [
                {
                    "id": "T1046",
                    "name": "Network Service Discovery",
                    "detection": {
                        "command": "ss -tnp state established | awk '{print $5}' | sort | uniq -c | sort -rn | head -20",
                        "indicators": [
                            "single IP connecting to many ports",
                            "sequential port pattern"
                        ],
                        "log_source": "ss, tcpdump, /var/log/ufw.log"
                    },
                    "playbook": "port-scan-detected.json",
                    "cispar_schema": "skills/cispar-network/schemas/scan_ports.json"
                }
            ]
        },
        {
            "id": "TA0008",
            "name": "Lateral Movement",
            "techniques": [
                {
                    "id": "T1021",
                    "name": "Remote Services",
                    "detection": {
                        "command": "who; w; last -i | head -20; ss -tnp | grep ':22\\|:3389'",
                        "indicators": [
                            "SSH from internal IP not in allow list",
                            "unexpected RDP session"
                        ],
                        "log_source": "who, last, ss, /var/log/auth.log"
                    },
                    "playbook": "lateral-movement.json",
                    "cispar_schema": "skills/cispar-l2-respond/schemas/investigate.json"
                }
            ]
        },
        {
            "id": "TA0010",
            "name": "Exfiltration",
            "techniques": [
                {
                    "id": "T1048",
                    "name": "Exfiltration Over Alternative Protocol",
                    "detection": {
                        "command": "ss -tnp state established | awk '{print $5}' | cut -d: -f1 | sort -u; nethogs -t -c 2 2>/dev/null || ss -ti",
                        "indicators": [
                            "large outbound transfer to unknown IP",
                            "DNS tunneling pattern",
                            "unusual protocol on common port"
                        ],
                        "log_source": "ss, nethogs, tcpdump, /var/log/ufw.log"
                    },
                    "playbook": "data-exfiltration.json",
                    "cispar_schema": "skills/cispar-l2-respond/schemas/contain.json",
                    "escalate": true,
                    "escalate_reason": "Data exfiltration has legal implications — always notify human"
                }
            ]
        }
    ]
}