Skip to content

Add ATT&CK heatmap dashboard visualization - #50

Merged
egrexsec merged 1 commit into
mainfrom
feature/attack-heatmap
May 29, 2026
Merged

egrexsec merged 1 commit into
mainfrom
feature/attack-heatmap

Conversation

@egrexsec

Copy link
Copy Markdown
Owner

Summary

Adds an ATT&CK-style coverage heatmap to the DetLab dashboard using live analytics data.

Changes

  • Added ATT&CK tactic heatmap grid
  • Added live tactic coverage rendering
  • Added dynamic coverage coloring
  • Added ATT&CK dashboard visualization foundations
  • Added graceful empty-state behavior

Example

docker compose up --build

@egrexsec
egrexsec merged commit 27ce893 into main May 29, 2026
1 check failed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 547e20340a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread web/app/page.tsx
? Object.entries(dashboard.maturity).map(([name, value]) => ({ name, value }))
: []

const tacticData = dashboard?.status || {}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use tactic counts for the heatmap

The heatmap is keyed by ATT&CK tactic names, but this line feeds it dashboard.status; /dashboard currently returns statuses such as experimental, testing, and stable (see detlab/api.py), so every tacticData[tactic] lookup falls back to 0 for normal detections. As a result the new heatmap always renders empty coverage until the endpoint exposes the existing analytics tactics counts and the client reads that field instead.

Useful? React with 👍 / 👎.

@egrexsec
egrexsec deleted the feature/attack-heatmap branch June 16, 2026 12:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant