
Coverage for the stack you actually run.
Modules teach the platform your technology — AWS, Kubernetes, containers, and self-managed infrastructure. Each one adds the classes, attributes, and threats for its domain, and every finding is cited to real evidence: CVEs, NIST controls, CWEs, and MITRE ATT&CK.
One class, resolved — from its attributes to the threats it raises to the evidence behind them.
A module isn’t a list of rules. Every class, attribute, threat, and control is a node in a knowledge graph, wired together: attributes drive the rules, the rules raise or clear each threat, and every threat is derived from primary evidence — a CVE, a NIST control, a CWE, a CIS benchmark, an ATT&CK technique.
That evidence is dated, versioned to a MITRE release, and traceable, so a finding on your model can always answer the one question that matters — why. When a class assigns exposures to your component, it is drawing on that graph, not guessing.
Depth you can
count on.
The catalog is broad and it is deep — and none of it is generic boilerplate.
Every finding cites its evidence — CVE · NIST 800-53 · CWE · CIS · MITRE ATT&CK · D3FEND.*
* ATT&CK® and D3FEND® are trademarks of The MITRE Corporation; CVE® and CWE™ are trademarks of their respective owners; CIS Benchmarks™ is a trademark of the Center for Internet Security. Dethernety modules cite and link to these public references — they do not include or redistribute the frameworks or benchmark content.
Load the modules for
the technology you run.
Assign a class from a loaded module and your component inherits that technology’s exposures and controls. Add modules as your stack grows.
AWS
Compute & containers (ECS, Fargate, Lambda, EKS), data & storage (Aurora, DynamoDB, RDS, S3), identity & cryptography (IAM, KMS, Cognito, ACM), and network & edge (API Gateway, CloudFront, ALB, VPC) — plus detection & governance, application integration, developer tools & supply chain, analytics & ML, IoT, media, and end-user computing.
Kubernetes & containers
Containerization (base images, registries, runtimes, build pipelines), Kubernetes Core (Pods, RBAC, NetworkPolicy, Secrets, Namespaces, admission), and Kubernetes Platform (kube-apiserver, etcd, CoreDNS, the CNI, ingress controllers, cloud-controller-manager). Managed clusters reuse the core rather than redefining it.
Self-managed infrastructure
Datastores (PostgreSQL, MySQL, MongoDB, Redis/Valkey, Cassandra, Elasticsearch, Neo4j), secrets & identity (Vault, OpenBao, Keycloak, Authentik, FreeIPA, step-ca), web & proxy (nginx, Envoy, HAProxy, Traefik, Caddy, Apache), plus messaging, observability, and CI/CD.
General — open source
dethernety-general covers the technology-agnostic classes — web servers, databases, load balancers, firewalls, identity providers, users, and generic trust zones — for modeling any system, or the parts no specialized module covers. It is open source — free to use, and to read.
Azure
Coming soonThe Azure service families — compute, storage, identity, networking, and beyond — are being modeled and cited through the same evidence-backed process as the rest of the catalog. Not loadable yet; it arrives as an update.
The general-purpose classes are open source.
dethernety-general — the vendor-neutral classes you reach for when no specialized module fits — is open source. You can use it, read it, and see exactly how a class turns into exposures before you commit to anything.
The specialized modules are maintained for you.
The AWS, Kubernetes, container, and self-managed modules are curated against primary sources and versioned to a MITRE release, then delivered as installable packages. New classes and refreshed evidence arrive as updates — you don’t maintain the threat intelligence yourself.
Run something we don’t cover yet?
Author your own classes, attributes, and controls in Dethernety Studio and export them as a module that behaves exactly like the built-in ones — or tell us what you need, and we’ll look at adding it to the catalog.
Model the stack you actually run.
Load the modules for your technology, assign classes on the canvas, and let the platform derive the exposures — each one cited to evidence you can follow.
