d3fend / d3fend-ontology

This repository holds the necessary content to produce the D3FEND ontology distribution.
https://d3fend.mitre.org
MIT License
59 stars 27 forks source link

ATT&CK technique tactics should be kept in sync with the ATT&CK release #299

Open aamedina opened 2 months ago

aamedina commented 2 months ago

In older versions of ATT&CK, techniques like T1216 and T1218 were classified under both "defense evasion" and "execution", but since ATT&CK 7.0-15.0 they have been classified under "defense evasion" (e.g https://attack.mitre.org/versions/v15/techniques/T1218/).

I think when the script to synchronize ATT&CK into d3fend is run on a new ATT&CK release from the STIX, the tactical phase is not synchronized. So it will accrete new tactics, not remove ones that aren't relevant anymore.

Solution will necessitate some upgrades to the synchronization script.

aamedina commented 2 months ago

Might be something to consider https://robot.obolibrary.org/template.html