SecurityRiskAdvisors / VECTR

VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios
1.39k stars 164 forks source link

Scorecard Report Data mismatch #105

Closed Antonlovesdnb closed 3 years ago

Antonlovesdnb commented 3 years ago

Hi team, this is something I might be doing wrong, but it looks like there's a data mismatch on the Scorecard Report screen - on the left hand side, the "Most Effective Defensive Layers" section seems to pull the tools used properly, but the text below shows either detected or 0% percent detected. The middle "Risk Score" section looks like it's pulling the data properly but not the Most and Least effective defensive layers section:

image

Hopefully I explained the issue correctly and am not missing any option somewhere or entering the data incorrectly - please let me know if I am and also please let me know if more info is required - thank you!

carlvonderheid commented 3 years ago

Hi, my guess is that you don't have your Blue Tools mapped to a Defensive Layer. On the left Nav, go to: Vendors & Tools -> Blue (the tab) -> then configure one of the tools that performed a detection. At the bottom of the config screen, you'll see a Category Selection section. These are your Defensive Layers that you want to make that tool contribute to. Let us know if they are mapped correctly.

Antonlovesdnb commented 3 years ago

Hey thanks very much for the quick reply, I think I see my problem - everything was mapped correctly in the tools section, but in my test case screen I only had the "Defenses" section configured and nothing selected for "Detecting Blue Tool(s)" - once I selected the detecting blue tool everything populated correctly, I got confused between the "Defenses" and "Detecting Blue Tool" categories and was expecting the report to populate based off the "Defenses" section - problem solved, thanks very much!