rabobank-cdc / DeTTECT

Detect Tactics, Techniques & Combat Threats
GNU General Public License v3.0
2.05k stars 333 forks source link

Feature request: Non-empty -1 scores comments visible in matrix #57

Open SanWieb opened 2 years ago

SanWieb commented 2 years ago

Hi,

In the current implementation, no distinction is made between not-specified technique detection scores and specified techniques with score -1. Both cases are not visible in the MITRE ATT&CK matrix.

It would be nice if all -1 detection scores where the date-field is non-empty would be visible in the matrix. Just only the comments without scoring / color would make it much clearer.

Currently, we often look at a technique in the attack-navigator and then do not know if the detection is that bad or if we just had not specified it yet. You could, of course, assume that every technique has been filled-in, but in practice I think this works differently.

rubinatorz commented 2 years ago

hi @SanWieb,

That's a nice idea and makes sense! We will put it on our backlog and keep you posted in this Github issue!

Regards, Ruben