APT战术映射与检测盲区分析
原名:analyzing-apt-group-with-mitre-navigator
``` 使用 ATT&CK API 查询攻击者 TTP,结合 mitreattack-python 和 stix2 构建 MITRE Navigator 图层与多层热力图叠加,映射 APT 组织战术行为,用于检测缺口分析与威胁情报报告。 ```
- 分类
- 数据分析
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-25
- TRACE 评分
- 3.6 / 5
内容概览
MITRE ATT&CK Navigator is a web-based tool for annotating and exploring ATT&CK matrices, enabling analysts to visualize threat actor technique coverage, compare multiple APT groups, identify detection gaps, and build threat-informed defense strategies. This skill covers querying ATT&CK data programmatically, mapping APT group TTPs to Navigator layers, creating multi-layer overlays for gap analysis, and generating actionable intelligence reports for detection engineering teams. - When investigating security incidents that require analyzing apt group with mitre navigator - When building detection rules or threat hunting queries for this domain - When SOC analysts need structured procedures for this analysis type - When validating security monitoring coverage for related attack techniques - Python 3.9+ with attackcti, mitreattack-python, stix2, requests libraries - ATT&CK Navigator (https:/…