ATT&CK威胁行为解析

原名:analyzing-threat-actor-ttps-with-mitre-attack

将威胁行为与IOCs系统映射至MITRE ATT&CK框架,构建技术覆盖热力图,识别检测盲区,并生成涵盖企业、移动及ICS矩阵的可操作威胁情报报告。

分类
数据分析
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
0
收藏
0
发布
2026-08-18
更新
2026-08-19
TRACE 评分
3.6 / 5

内容概览

MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor behavior to the ATT&CK framework, building technique coverage heatmaps using the ATT&CK Navigator, identifying detection gaps, and producing actionable intelligence reports that link observed IOCs to specific adversary techniques across the Enterprise, Mobile, and ICS matrices. - When investigating security incidents that require analyzing threat actor ttps with mitre attack - When building detection rules or threat hunting queries for this domain - When SOC analysts need structured procedures for this analysis type - When validating security monitoring coverage for related attack techniques - Python 3.9+ with mitreattack-python, attackcti, stix2 libraries - MITRE ATT&CK Navigator (web-based or…

查看 SKILL 详情