Skip to content

Future dev

Marcus Bakker edited this page Dec 20, 2021 · 10 revisions

Future developments

See below a list of some possible future developments.

DeTT&CT CLI

  • Data sources
    • Can make use of applicable_to for data sources.
    • Similar to the technique YAML file have score_logbook for data sources.
  • ATT&CK Mitigations
    • Add the possibility to administrate and score preventive and protective controls.
  • Scoring changelog:
    • Have a changelog for recording any notable changes in your scores for visibility, detection and data source quality.
    • Have those changes for (possible) improvements be reflected in the graphs for detections and data sources.
  • MITRE ATT&CK updates
    • Have a smart way of knowing what to update in your data source and technique administration files once MITRE publishes.
  • Minimal visibility
    • Integrate knowledge (or the possibility to do this yourself) into the framework that tells you which data sources you should at least have for a technique before you can say to have useful visibility. (E.g. technique X requires at least to have visibility on Process OS API Execution and Process Access).

DeTT&CT Editor

  • Data sources
    • Show a message when a data source does not apply to one of the selected platforms.
    • Show in the left table of data sources when a data source does not apply to one of the selected platforms.
    • Edit the technique's exception list.
  • Techniques
    • Show in the left table of techniques when a technique may not apply to one of the selected platforms.
  • Groups.
    • Edit and create a group YAML file with weighted scores for ATT&CK techniques.
  • Tabs
    • Allow having multiple files open from the same type.
  • User experience
    • Multiple improvements in the user experience. This is continuous development, and hence multiple improvements have already been implemented and released.
Clone this wiki locally