Sign inSign up

rabobankcdc/dettect

By rabobankcdc

•Updated about 14 hours ago

Detect Tactics, Techniques & Combat Threats

Image
3

10K+

rabobankcdc/dettect repository overview

DeTT&CT
⁠Detect Tactics, Techniques & Combat Threats

To get started with DeTT&CT, check out one of these resources:

Videos

DeTT&CT aims to assist blue teams in using ATT&CK to score and compare data log source quality, visibility coverage, detection coverage and threat actor behaviours. All of which can help, in different ways, to get more resilient against attacks targeting your organisation. The DeTT&CT framework consists of a Python tool (DeTT&CT CLI), YAML administration files, the DeTT&CT Editor⁠ (to create and edit the YAML administration files) and scoring tables⁠ for detections⁠, data sources⁠ and visibility⁠.

DeTT&CT provides the following functionality for the ATT&CK domains Enterprise, ICS and Mobile:

  • Administrate and score the quality of your data sources*.
  • Get insight on the visibility you have on for example endpoints.
  • Map your detection coverage.
  • Map threat actor behaviours.
  • Compare visibility, detection coverage and threat actor behaviours to uncover possible improvements in detection and visibility (which is based on your available data sources). This can help you to prioritise your blue teaming efforts.
  • Get statistics (per platform) on the number of techniques covered per data source.

The coloured visualisations are created with the help of MITRE's ATT&CK™ Navigator⁠. For layer files created by DeTT&CT, we recommend using this URL to the Navigator as it will make sure metadata in the layer file does not have a yellow underline: https://mitre-attack.github.io/attack-navigator/#comment_underline=false⁠

* ATT&CK has not yet implemented data sources for Mobile. This will come in a future release of ATT&CK. Once it's there, we will incorporate it in DeTT&CT.

⁠Authors and contributions

This project is developed and maintained by Marcus Bakker⁠ (Twitter: @Bakk3rM⁠) and Ruben Bouman⁠ (Twitter: @rubinatorz⁠). Feel free to contact, DMs are open. We do appreciate if you ask any question on how to use DeTT&CT by making a GitHub issue. Having the questions and answers over there will greatly help others having similar questions and challenges.

We welcome contributions! Contributions can be both in code and in ideas you might have for further development, usability improvements, etc.

⁠Sponsors

The following parties have supported the development of DeTT&CT in time or financially.

  • Rabobank⁠ - Dutch multinational banking and financial services company. Food and agribusiness constitute the primary international focus of the Rabobank.

    Significant parts of DeTT&CT have been developed in the time that we worked as contractors at Rabobank.

  • Cyber Security Sharing & Analytics (CSSA)⁠ - Founded in November 2014 by seven major German companies as an alliance for jointly facing cyber security challenges in a proactive, fast and effective manner. Currently, CSSA has 13 member companies.

    With the financial sponsorship of the CSSA, we added support for ATT&CK ICS⁠ to DeTT&CT.

  • Dutch National Police⁠. With the financial sponsorship of the Dutch National Police, we added support for ATT&CK Mobile to DeTT&CT.

⁠Work of others

The work of others inspired some functionality within DeTT&CT:

⁠Third party tool: Dettectinator

The Python library to your DeTT&CT YAML files.

Dettectinator is built to be included in your SOC automation tooling. It can be included as a Python library or it can be used via the command line.

Dettectinator provides plugins to read detections from your SIEM or EDR and create/update the DeTT&CT YAML file, so that you can use it to visualize your ATT&CK detection coverage in the ATT&CK Navigator.

More information can be found on Github: Dettectinator⁠.

⁠License: GPL-3.0

DeTT&CT's GNU General Public License v3.0⁠

Tag summary

Content type

Image

Digest

sha256:2bc87bef8…

Size

108.9 MB

Last updated

about 14 hours ago

docker pull rabobankcdc/dettect