Skip to content

Commit de08f4e

Browse files
phantinussgithub-actions[bot]
authored andcommitted
chore: update ATT&CK heatmap
1 parent 6d58176 commit de08f4e

1 file changed

Lines changed: 49 additions & 38 deletions

File tree

other/sigma_attack_nav_coverage.json

Lines changed: 49 additions & 38 deletions
Original file line numberDiff line numberDiff line change
@@ -96,7 +96,7 @@
9696
{
9797
"techniqueID": "T1190",
9898
"tactic": "initial-access",
99-
"score": 143,
99+
"score": 145,
100100
"color": "",
101101
"comment": "",
102102
"enabled": true,
@@ -305,7 +305,7 @@
305305
{
306306
"techniqueID": "T1003",
307307
"tactic": "credential-access",
308-
"score": 34,
308+
"score": 35,
309309
"color": "",
310310
"comment": "",
311311
"enabled": true,
@@ -404,7 +404,7 @@
404404
{
405405
"techniqueID": "T1562.001",
406406
"tactic": "defense-evasion",
407-
"score": 114,
407+
"score": 118,
408408
"color": "",
409409
"comment": "",
410410
"enabled": true,
@@ -800,7 +800,7 @@
800800
{
801801
"techniqueID": "T1059",
802802
"tactic": "execution",
803-
"score": 91,
803+
"score": 93,
804804
"color": "",
805805
"comment": "",
806806
"enabled": true,
@@ -1053,7 +1053,7 @@
10531053
{
10541054
"techniqueID": "T1105",
10551055
"tactic": "command-and-control",
1056-
"score": 71,
1056+
"score": 74,
10571057
"color": "",
10581058
"comment": "",
10591059
"enabled": true,
@@ -1196,7 +1196,7 @@
11961196
{
11971197
"techniqueID": "T1102.002",
11981198
"tactic": "command-and-control",
1199-
"score": 3,
1199+
"score": 4,
12001200
"color": "",
12011201
"comment": "",
12021202
"enabled": true,
@@ -1350,7 +1350,7 @@
13501350
{
13511351
"techniqueID": "T1003.001",
13521352
"tactic": "credential-access",
1353-
"score": 77,
1353+
"score": 78,
13541354
"color": "",
13551355
"comment": "",
13561356
"enabled": true,
@@ -2439,7 +2439,7 @@
24392439
{
24402440
"techniqueID": "T1036.003",
24412441
"tactic": "defense-evasion",
2442-
"score": 27,
2442+
"score": 28,
24432443
"color": "",
24442444
"comment": "",
24452445
"enabled": true,
@@ -2846,7 +2846,7 @@
28462846
{
28472847
"techniqueID": "T1566.001",
28482848
"tactic": "initial-access",
2849-
"score": 22,
2849+
"score": 23,
28502850
"color": "",
28512851
"comment": "",
28522852
"enabled": true,
@@ -2945,7 +2945,7 @@
29452945
{
29462946
"techniqueID": "T1087",
29472947
"tactic": "discovery",
2948-
"score": 15,
2948+
"score": 16,
29492949
"color": "",
29502950
"comment": "",
29512951
"enabled": true,
@@ -3638,7 +3638,7 @@
36383638
{
36393639
"techniqueID": "T1071",
36403640
"tactic": "command-and-control",
3641-
"score": 6,
3641+
"score": 7,
36423642
"color": "",
36433643
"comment": "",
36443644
"enabled": true,
@@ -5297,9 +5297,9 @@
52975297
"showSubtechniques": false
52985298
},
52995299
{
5300-
"techniqueID": "T1546.004",
5301-
"tactic": "privilege-escalation",
5302-
"score": 1,
5300+
"techniqueID": "T1574.006",
5301+
"tactic": "persistence",
5302+
"score": 2,
53035303
"color": "",
53045304
"comment": "",
53055305
"enabled": true,
@@ -5308,9 +5308,9 @@
53085308
"showSubtechniques": false
53095309
},
53105310
{
5311-
"techniqueID": "T1546.004",
5312-
"tactic": "persistence",
5313-
"score": 1,
5311+
"techniqueID": "T1574.006",
5312+
"tactic": "privilege-escalation",
5313+
"score": 2,
53145314
"color": "",
53155315
"comment": "",
53165316
"enabled": true,
@@ -5319,8 +5319,8 @@
53195319
"showSubtechniques": false
53205320
},
53215321
{
5322-
"techniqueID": "T1543.002",
5323-
"tactic": "persistence",
5322+
"techniqueID": "T1574.006",
5323+
"tactic": "defense-evasion",
53245324
"score": 2,
53255325
"color": "",
53265326
"comment": "",
@@ -5330,9 +5330,9 @@
53305330
"showSubtechniques": false
53315331
},
53325332
{
5333-
"techniqueID": "T1543.002",
5333+
"techniqueID": "T1546.004",
53345334
"tactic": "privilege-escalation",
5335-
"score": 2,
5335+
"score": 1,
53365336
"color": "",
53375337
"comment": "",
53385338
"enabled": true,
@@ -5341,9 +5341,9 @@
53415341
"showSubtechniques": false
53425342
},
53435343
{
5344-
"techniqueID": "T1030",
5345-
"tactic": "exfiltration",
5346-
"score": 2,
5344+
"techniqueID": "T1546.004",
5345+
"tactic": "persistence",
5346+
"score": 1,
53475347
"color": "",
53485348
"comment": "",
53495349
"enabled": true,
@@ -5352,9 +5352,9 @@
53525352
"showSubtechniques": false
53535353
},
53545354
{
5355-
"techniqueID": "T1547.006",
5355+
"techniqueID": "T1543.002",
53565356
"tactic": "persistence",
5357-
"score": 1,
5357+
"score": 2,
53585358
"color": "",
53595359
"comment": "",
53605360
"enabled": true,
@@ -5363,9 +5363,9 @@
53635363
"showSubtechniques": false
53645364
},
53655365
{
5366-
"techniqueID": "T1547.006",
5366+
"techniqueID": "T1543.002",
53675367
"tactic": "privilege-escalation",
5368-
"score": 1,
5368+
"score": 2,
53695369
"color": "",
53705370
"comment": "",
53715371
"enabled": true,
@@ -5374,8 +5374,8 @@
53745374
"showSubtechniques": false
53755375
},
53765376
{
5377-
"techniqueID": "T1574.006",
5378-
"tactic": "persistence",
5377+
"techniqueID": "T1499",
5378+
"tactic": "impact",
53795379
"score": 2,
53805380
"color": "",
53815381
"comment": "",
@@ -5385,8 +5385,8 @@
53855385
"showSubtechniques": false
53865386
},
53875387
{
5388-
"techniqueID": "T1574.006",
5389-
"tactic": "privilege-escalation",
5388+
"techniqueID": "T1030",
5389+
"tactic": "exfiltration",
53905390
"score": 2,
53915391
"color": "",
53925392
"comment": "",
@@ -5396,9 +5396,9 @@
53965396
"showSubtechniques": false
53975397
},
53985398
{
5399-
"techniqueID": "T1574.006",
5400-
"tactic": "defense-evasion",
5401-
"score": 2,
5399+
"techniqueID": "T1547.006",
5400+
"tactic": "persistence",
5401+
"score": 1,
54025402
"color": "",
54035403
"comment": "",
54045404
"enabled": true,
@@ -5407,9 +5407,9 @@
54075407
"showSubtechniques": false
54085408
},
54095409
{
5410-
"techniqueID": "T1499",
5411-
"tactic": "impact",
5412-
"score": 2,
5410+
"techniqueID": "T1547.006",
5411+
"tactic": "privilege-escalation",
5412+
"score": 1,
54135413
"color": "",
54145414
"comment": "",
54155415
"enabled": true,
@@ -5626,6 +5626,17 @@
56265626
"links": [],
56275627
"showSubtechniques": false
56285628
},
5629+
{
5630+
"techniqueID": "T1598.002",
5631+
"tactic": "reconnaissance",
5632+
"score": 1,
5633+
"color": "",
5634+
"comment": "",
5635+
"enabled": true,
5636+
"metadata": [],
5637+
"links": [],
5638+
"showSubtechniques": false
5639+
},
56295640
{
56305641
"techniqueID": "T1090.004",
56315642
"tactic": "command-and-control",

0 commit comments

Comments
 (0)