Skip to content

Maps MITRE ATT&CK techniques describing post-compromise adversary behavior to relevant MITRE Shield defensive techniques

Notifications You must be signed in to change notification settings

goodlandsecurity/attack-mapper

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 

Repository files navigation

attack-mapper

attack-mapper.py maps MITRE ATT&CK techniques describing post-compromise adversary behavior to relevant MITRE Shield defensive techniques

Author: th3jiv3r.


What is Active Defense?

The U.S. Department of Defense defines active defense as:

“The employment of limited offensive action and counterattacks to deny a contested area or position to the enemy.”

Active defense ranges from basic cyber defensive capabilities to cyber deception and adversary engagement operations.

The combination of these defenses allows an organization to not only counter current attacks, but also to learn more about that adversary and better prepare for new attacks in the future.


What is MITRE Shield?

Shield is an active defense knowledge base MITRE is developing to capture and organize what we are learning about active defense and adversary engagement. Derived from over 10 years of adversary engagement experience, it spans the range from high level, CISO ready considerations of opportunities and objectives, to practitioner friendly discussions of the TTPs available to defenders.


Demo:

Searching by ATT&CK Technique Name:
asciicast

Searching by ATT&CK Technique ID:
asciicast

About

Maps MITRE ATT&CK techniques describing post-compromise adversary behavior to relevant MITRE Shield defensive techniques

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages