Skip to content

vinayb-devsecops/attackmapper

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

11 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

AttackMapper

Detection Engineering and MITRE ATT&CK Coverage Platform.

Overview

AttackMapper is a detection engineering platform designed to map adversary techniques to monitoring controls, detection logic, threat hunting workflows, and ATT&CK coverage visibility.

The platform helps security teams understand detection coverage, identify monitoring gaps, improve detection strategy, and align security operations with the MITRE ATT&CK framework.

Platform Capabilities

ATT&CK Technique Repository

  • Technique Catalog
  • Technique Search
  • Technique Details
  • ATT&CK Coverage Visibility

Detection Engineering

  • Detection Mapping
  • Monitoring Control Mapping
  • Coverage Validation
  • Detection Gap Identification

Threat Hunting Support

  • ATT&CK-Aligned Investigations
  • Hunt Planning
  • Technique Analysis
  • Detection Improvement

Security Operations Analytics

  • Detection Coverage Metrics
  • ATT&CK Visibility
  • Coverage Reporting
  • Security Monitoring Insights

Core Modules

ATT&CK Knowledge Repository

Provides a searchable repository of ATT&CK techniques and associated detection information.

Coverage Analytics Engine

Measures detection coverage and identifies monitoring gaps across ATT&CK techniques.

Detection Mapping Engine

Maps monitoring controls and detection logic to ATT&CK techniques.

Security Operations Dashboard

Provides visibility into ATT&CK coverage and detection engineering metrics.

Architecture

MITRE ATT&CK Dataset ↓ Technique Repository ↓ Detection Mapping Layer ↓ Coverage Analytics ↓ REST API ↓ Security Operations Dashboard

Detection Engineering Use Cases

  • ATT&CK Coverage Assessment
  • Detection Gap Analysis
  • Threat Hunting Support
  • Detection Strategy Development
  • Monitoring Improvement
  • Security Operations Reporting

Dashboard

AttackMapper Dashboard

API Endpoints

Get All Techniques

/api/techniques

Technology Stack

  • Python
  • Flask
  • Bootstrap 5
  • JSON

Repository Structure

data/ templates/ screenshots/ docs/

Current ATT&CK Coverage

  • Initial Access
  • Execution
  • Persistence
  • Privilege Escalation
  • Defense Evasion
  • Credential Access
  • Discovery
  • Lateral Movement
  • Collection
  • Impact

Roadmap

  • ATT&CK Navigator Export
  • Coverage Heatmaps
  • Detection Maturity Scoring
  • Threat Hunting Analytics
  • Detection Effectiveness Metrics
  • PostgreSQL Backend

Release Information

Current Release: v1.0

About

Detection Engineering and MITRE ATT&CK Coverage Platform

Topics

Resources

Stars

Watchers

Forks

Packages

 
 
 

Contributors