Tool lets users supplement Mitre ATT&CK knowledge base with their own threat intel
The research and development division of Mitre Engenuity launched a tool that allows organizations to integrate their own proprietary threat intelligence with the Mitre ATT&CK framework’s public knowledge base – thereby creating their own customized repository of cyber threat information.
Called ATT&CK Workbench, the free and open-source tool was designed to reduce the barriers preventing defenders from aligning their aggregated TTP intel with Mitre ATT&CK’s content. Officially announced today via press release and blog post, Workbench is a creation of Mitre Engenuity’s Center for Threat-Informed Defense, with contributions from Center members AttackIQ, HCA Healthcare, JPMorgan Chase, Microsoft and Verizon. Mitre exclusively shared the news with SC Media in advance of its official announcement.
Enabled via a REST API, the tool lets ATT&CK users create and build off their own unique instance of the framework, adding and annotating content, while also sharing their version internally or externally with other collaborators. Such functionality will should provide users with additional flexibility in how they personally wish to collect, prioritize and communicate threat information based on their own companies’ needs and past experiences.