{"repo":"center-for-threat-informed-defense/sightings_ecosystem","free":true,"listed":false,"github":"https://github.com/center-for-threat-informed-defense/sightings_ecosystem","clone":"git clone https://github.com/center-for-threat-informed-defense/sightings_ecosystem.git","description":"Sightings Ecosystem gives cyber defenders visibility into what adversaries actually do in the wild. With your help, we are tracking MITRE ATT&CK® techniques observed to give defenders real data on technique prevalence.","language":"Python","stars":38,"topics":["cybersecurity","ctid","mitre-attack","cyber-threat-intelligence","data-science","data-visualization"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Sightings Ecosystem The Sightings Ecosystem gives cyber defenders visibility into what adversaries are actually doing in the wild. With your help, we are tracking MITRE ATT&CK® techniques observed to give defenders real data on technique prevalence. With this data, we can analyze trends in evolving adversary behaviors, and ultimately provide a data-driven resource to support prioritizing defensive operations. This project ingests ATT&CK technique sightings and process them to produce useful datasets and reporting. - Sightings Ecosystem - Getting Started - Background - Getting Involved - Questions and Feedback - Notice Getting Started To get started, we suggest skimming the documentation to get familiar with the project. Next, you may want to try creating your own attack flows using the Attack Flow Builder, which is an easy-to-use GUI tool. When you are ready to dive deep, review the Example Flows and JSON Schema for the language. Resource Description ------------------------------------------------------------------------------------------------------------ ---------------------------------------------------------------------------------------- Project Web Site Complete documentation for the Sightings Ecosystem. Sightings Data Download the underlying Sightings data. (CSV – 25.7MiB) Upload Tool A tool for automatically submitting sightings data (supports Linux, MacOS, and Windows). Background Defenders need data driven answers to questions like: - How do I know which technique","default_branch":null,"files":null,"tree":[],"storefront":"/r/center-for-threat-informed-defense","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/center-for-threat-informed-defense/sightings_ecosystem/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}