mitre / cti

Cyber Threat Intelligence Repository expressed in STIX 2.0
Other
1.71k stars 410 forks source link

ATT&CK attack-patterns no longer have external_references to CAPEC #221

Closed samwagg closed 1 year ago

samwagg commented 1 year ago

I noticed that all Techniques that have external_references to CAPEC have either been revoked or deprecated. Is it an intentional/systematic policy to no longer include CAPEC references in the ATT&CK dataset?

adampennin commented 1 year ago

They were removed in v13 of ATT&CK back in April and it's an oversight that this wasn't mentioned in the release notes. Those references will not be included in the future unless they're a part of citations in technique descriptions. The CAPEC team maintains their own mapping from CAPEC to ATT&CK, which is still in place.