Add optional MITRE ATT&CK classification to findings #306
MichaelGrafnetter
started this conversation in
Ideas
Replies: 2 comments
-
What you mean is that we provide a predefined field holding all techniques and tactics hierarchically structured? This shouldn't be too hard to implement. What we must not forget is to include the license/terms of use. |
Beta Was this translation helpful? Give feedback.
0 replies
-
Yep, that's the idea. Both classifications are actually managed by the same MITRE organization. In the PDF report, the IDs should be hyperlinked to the source material. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Many infrastructure pentesters use the MITRE ATT&CK framework. The ability to map a vulnerability/attack step to a technique ID, e.g. Account Manipulation: SSH Authorized Keys, would be great.
Beta Was this translation helpful? Give feedback.
All reactions