Extend modeling coverage

Coverage for the stack you actually run.

Modules teach the platform your technology — AWS, Kubernetes, containers, and self-managed infrastructure. Each one adds the classes, attributes, and threats for its domain, and every finding is cited to real evidence: CVEs, NIST controls, CWEs, and MITRE ATT&CK.

A knowledge-graph chain: the Kubernetes NetworkPolicy class has attributes (default-deny ingress, default-deny egress with DNS allow-list, enforcing CNI present); rules over those attributes raise or clear the threat 'flat pod network — cross-tenant lateral movement' mapped to ATT&CK T1021; and that threat is derived from cited evidence — CVE-2021-25740, NIST 800-53 AC-6, CIS Kubernetes 5.3.2, and D3FEND D3-NTF.

One class, resolved — from its attributes to the threats it raises to the evidence behind them.

Not a checklist — a resolved graph

A module isn’t a list of rules. Every class, attribute, threat, and control is a node in a knowledge graph, wired together: attributes drive the rules, the rules raise or clear each threat, and every threat is derived from primary evidence — a CVE, a NIST control, a CWE, a CIS benchmark, an ATT&CK technique.

That evidence is dated, versioned to a MITRE release, and traceable, so a finding on your model can always answer the one question that matters — why. When a class assigns exposures to your component, it is drawing on that graph, not guessing.

Depth you can
count on.

The catalog is broad and it is deep — and none of it is generic boilerplate.

20+
specialized modules
300+
modeled classes
6,000+
configurable attributes
2,900+
evaluated threats
650+
cited sources
230+
ATT&CK techniques

Every finding cites its evidence — CVE · NIST 800-53 · CWE · CIS · MITRE ATT&CK · D3FEND.*

* ATT&CK® and D3FEND® are trademarks of The MITRE Corporation; CVE® and CWE™ are trademarks of their respective owners; CIS Benchmarks™ is a trademark of the Center for Internet Security. Dethernety modules cite and link to these public references — they do not include or redistribute the frameworks or benchmark content.

Load the modules for
the technology you run.

Assign a class from a loaded module and your component inherits that technology’s exposures and controls. Add modules as your stack grows.

AWS

Eleven service families

Compute & containers (ECS, Fargate, Lambda, EKS), data & storage (Aurora, DynamoDB, RDS, S3), identity & cryptography (IAM, KMS, Cognito, ACM), and network & edge (API Gateway, CloudFront, ALB, VPC) — plus detection & governance, application integration, developer tools & supply chain, analytics & ML, IoT, media, and end-user computing.

Kubernetes & containers

From the image to the control plane

Containerization (base images, registries, runtimes, build pipelines), Kubernetes Core (Pods, RBAC, NetworkPolicy, Secrets, Namespaces, admission), and Kubernetes Platform (kube-apiserver, etcd, CoreDNS, the CNI, ingress controllers, cloud-controller-manager). Managed clusters reuse the core rather than redefining it.

Self-managed infrastructure

The services you run yourself

Datastores (PostgreSQL, MySQL, MongoDB, Redis/Valkey, Cassandra, Elasticsearch, Neo4j), secrets & identity (Vault, OpenBao, Keycloak, Authentik, FreeIPA, step-ca), web & proxy (nginx, Envoy, HAProxy, Traefik, Caddy, Apache), plus messaging, observability, and CI/CD.

General — open source

Vendor-neutral building blocks

dethernety-general covers the technology-agnostic classes — web servers, databases, load balancers, firewalls, identity providers, users, and generic trust zones — for modeling any system, or the parts no specialized module covers. It is open source — free to use, and to read.

Azure

Coming soon

The Azure service families — compute, storage, identity, networking, and beyond — are being modeled and cited through the same evidence-backed process as the rest of the catalog. Not loadable yet; it arrives as an update.

Open core

The general-purpose classes are open source.

dethernety-general — the vendor-neutral classes you reach for when no specialized module fits — is open source. You can use it, read it, and see exactly how a class turns into exposures before you commit to anything.

Curated catalog

The specialized modules are maintained for you.

The AWS, Kubernetes, container, and self-managed modules are curated against primary sources and versioned to a MITRE release, then delivered as installable packages. New classes and refreshed evidence arrive as updates — you don’t maintain the threat intelligence yourself.

Run something we don’t cover yet?

Author your own classes, attributes, and controls in Dethernety Studio and export them as a module that behaves exactly like the built-in ones — or tell us what you need, and we’ll look at adding it to the catalog.

Model the stack you actually run.

Load the modules for your technology, assign classes on the canvas, and let the platform derive the exposures — each one cited to evidence you can follow.