APT战术映射与检测盲区分析

原名:analyzing-apt-group-with-mitre-navigator

``` 使用 ATT&CK API 查询攻击者 TTP,结合 mitreattack-python 和 stix2 构建 MITRE Navigator 图层与多层热力图叠加,映射 APT 组织战术行为,用于检测缺口分析与威胁情报报告。 ```

分类
数据分析
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
0
收藏
0
发布
2026-08-18
更新
2026-08-25
TRACE 评分
3.6 / 5

内容概览

MITRE ATT&CK Navigator is a web-based tool for annotating and exploring ATT&CK matrices, enabling analysts to visualize threat actor technique coverage, compare multiple APT groups, identify detection gaps, and build threat-informed defense strategies. This skill covers querying ATT&CK data programmatically, mapping APT group TTPs to Navigator layers, creating multi-layer overlays for gap analysis, and generating actionable intelligence reports for detection engineering teams. - When investigating security incidents that require analyzing apt group with mitre navigator - When building detection rules or threat hunting queries for this domain - When SOC analysts need structured procedures for this analysis type - When validating security monitoring coverage for related attack techniques - Python 3.9+ with attackcti, mitreattack-python, stix2, requests libraries - ATT&CK Navigator (https:/…

查看 SKILL 详情