Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reverse scoring #377

Open
joshua17sc opened this issue Jul 1, 2022 · 0 comments
Open

Reverse scoring #377

joshua17sc opened this issue Jul 1, 2022 · 0 comments

Comments

@joshua17sc
Copy link

It would be great to have an option where selecting multiple TTPs, whether during an incident or following an incident during threat intelligence analysis, to run correlation against the layers for each of the threat actors already included in Navigator.
For example:
Investigator finds that valid accounts were used (T1078), Brute Force Password Spraying (T1110.003), and Exfil over C2 (T1041). These are all selected, and then run correlation/reverse scoring, and it spits out that these are 3/27 techniques for Lazarus, 2/32 techniques for Leviathan, and 0/26 techniques for FIN7...
I'm thinking of a python script that does this with the downloaded json, but it would be helpful to have it in the platform.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant