Skip to content

Mapping TTPs and CVEs #2184

Answered by wbooth
afarao asked this question in Q&A
Discussion options

You must be logged in to vote

If you want to link TTPs to CVEs there is the ability to tag ability yaml files when they are created. This can be observed in the pathfinder repo with the heartbleed ability contained in the repo (which is tagged with a CVE):
https://github.com/center-for-threat-informed-defense/caldera_pathfinder/blob/master/data/abilities/initial-access/315f8fcc-c05a-4db0-9f9a-5daade661540.yml#L12

The limitation is that abilities that are created implementing CVEs need to have information tagged on them when they are created for it to be useful. Also, to the extent of my knowledge, the only plugin using the tags on objects is pathfinder.

From: @mrengstrom

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by blackwidow0616
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants