ATT&CK威胁行为解析
原名:analyzing-threat-actor-ttps-with-mitre-attack
将威胁行为与IOCs系统映射至MITRE ATT&CK框架,构建技术覆盖热力图,识别检测盲区,并生成涵盖企业、移动及ICS矩阵的可操作威胁情报报告。
- 分类
- 数据分析
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-19
- TRACE 评分
- 3.6 / 5
内容概览
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor behavior to the ATT&CK framework, building technique coverage heatmaps using the ATT&CK Navigator, identifying detection gaps, and producing actionable intelligence reports that link observed IOCs to specific adversary techniques across the Enterprise, Mobile, and ICS matrices. - When investigating security incidents that require analyzing threat actor ttps with mitre attack - When building detection rules or threat hunting queries for this domain - When SOC analysts need structured procedures for this analysis type - When validating security monitoring coverage for related attack techniques - Python 3.9+ with mitreattack-python, attackcti, stix2 libraries - MITRE ATT&CK Navigator (web-based or…