Анализ APT-группировок через MITRE ATT&CK Navigator

★ 8.4 · research

analyzing-apt-group-with-mitre-navigator is a Claude Code skill that queries MITRE ATT&CK data using attackcti, mitreattack-python, and stix2, then builds Navigator layer JSON files and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap analysis. The skill covers the full workflow: fetching group techniques by G-code, generating layer 4.5 files with scores, colors, and metadata, and creating multi-layer overlays across the ATT&CK Enterprise, Mobile, and ICS domains. SOC analysts and threat intelligence teams use it to compare technique coverage across threat actors, prioritize detection engineering efforts, and produce Navigator visualizations for threat-informed defense reporting. Python 3.9+ with the relevant libraries and access to ATT&CK Navigator are required.