Blue ATT&CK

#### Mapping your blue team to ATT&CK

To get started with Blue ATT&CK, check out the [Wiki](

Blue ATT&CK will help blue teams in scoring and comparing data source quality, visibility coverage, detection coverage and threat actor behaviours. The Blue ATT&CK framework consists of a Python tool, YAML administration files and [scoring tables]( for the different aspects.

Blue ATT&CK will help you to:
- Administrate and score the quality of your data sources.
- Get insight on the visibility you have on for example endpoints.
- Map your detection coverage.
- Map threat actor behaviours.
- Compare visibility, detections and threat actor behaviours in order to uncover possible improvements in detection and visibility. This can help you to prioritise your blue teaming efforts.

## Authors and contribution

This project is developed and maintained by [Marcus Bakker]( (Twitter: [@bakker3m]( and [Ruben Bouman]( (Twitter: [@rubenb_2](

We welcome contributions! Contributions can be both in code, as well as in ideas you might have for further development, usability improvements, etc.

### Work of others

Some functionality within Blue ATT&CK was inspired by work of others:
- Roberto Rodriguez's work on data quality and scoring of ATT&CK techniques ([How Hot Is Your Hunt Team?](, [Ready to hunt? First, Show me your data!](
- The MITRE ATT&CK Mapping project on GitHub:

## Example

YAML files are used for administrating scores and relevant metadata. All of which can be visualised by loading JSON layer files into the [ATT&CK Navigator]( (some types of scores and metadata can also be written to Excel). See below an example of mapping your data sources to ATT&CK which gives you a rough overview of your visibility coverage:
## Installation and requirements

See our GitHub Wiki: [Installation and requirements](

## License: GPL-3.0

[Blue ATT&CK's GNU General Public License v3.0](