Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feature Request] Incorporate MITRE map or json export for selected TTP's in a case #8

Open
aacgood opened this issue Jun 21, 2022 · 1 comment
Assignees
Labels
enhancement New feature or request

Comments

@aacgood
Copy link

aacgood commented Jun 21, 2022

Request Type

Feature Request

Feature Description

Within a case, for whatever TTP's are added to an incident, include a heatmap output for the MITRE attack framework so that you can see at a glance what areas of the framework are touched within an incident.

Alternativley, output a json file so that it can be manually added via the Attack Navigator

Feature could possibly be added into a dashboard so that any TTP's seen over all cases in a selected timeframe could be overlayed in a heatmap giving a SOC Manager visibility / reportability into what areas they are being targetted the most. Creating a heatmap in the Attack Navigator is possible to construct via json.

Complementary information

image

@vdebergue
Copy link
Contributor

Hello, thank you for the feedback.

Integrating the navigator in TheHive UI seems a bit too complex at the moment but creating a json layer file seems doable.
We could first include it for a single case and then add the ability to generate the layer from multiple cases to get the heatmap.

For reference, Mitre uses some ptyhon scripts to generate the json layers: https://github.com/mitre-attack/attack-scripts/tree/master/scripts/layers/samples

I will add this feature on the roadmap, it may be available in 5.2 (5.1 is almost ready so a bit late to include this feature there)

@vdebergue vdebergue added the enhancement New feature or request label Jun 21, 2022
@vdebergue vdebergue self-assigned this Jun 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants