The DeTT&CT framework consists of a Python tool, YAML administration files, and the DeTT&CT Editor.
1.7K
DeTT&CT aims to assist blue teams in using ATT&CK to score and compare data log source quality, visibility coverage, detection coverage and threat actor behaviours. All of which can help, in different ways, to get more resilient against attacks targeting your organisation. The DeTT&CT framework consists of a Python tool (DeTT&CT CLI), YAML administration files, the DeTT&CT Editor (to create and edit the YAML administration files) and scoring tables for detections, data sources and visibility.
DeTT&CT provides the following functionality for the ATT&CK domains Enterprise, ICS and Mobile:
Administrate and score the quality of your data sources.
Get insight on the visibility you have on for example endpoints.
Map your detection coverage.
Map threat actor behaviours.
Compare visibility, detection coverage and threat actor behaviours to uncover possible improvements in detection and visibility (which is based on your available data sources). This can help you to prioritise your blue teaming efforts.
Get statistics (per platform) on the number of techniques covered per data source.
Content type
Image
Digest
sha256:da9ab02f4…
Size
111 MB
Last updated
about 2 years ago
docker pull ibedson888/dettect