The Cybersecurity and Infrastructure Security Agency (CISA) has unwrapped Decider, a new, free tool to help security practitioners, security analysts and researchers map adversary tactics, techniques and procedures (TTP) to the Att&ck knowledge base.
CISA and Homeland Security Collaborate
CISA said it created Decider in collaboration with the Department of Homeland Security’s Engineering and Development Institute and the Mitre Att&ck team. Decider is a web application that must be hosted to use.
Att&ck has been adopted by CISA and network defenders worldwide because it helps cyber threat intelligence analysts understand adversary cyberattackers' strategies and movements. Using the Att&ck database, however, can present challenges in that mapping different forms of observable data asks the user to understand both the behavior itself and how to use the library, CISA said.
“Since the original publication of the best practices guide in June 2021, CISA has found that while ATT&CK is a valuable tool for enterprise cybersecurity, there are many intricacies in creating ATT&CK mappings that are important to get right and easy to get wrong,” the agency said.
Decider's Advantages
Here are some of Decider’s benefits and features:
According to a CISA fact sheet that accompanied Decider’s release, with Mitre Att&ck mapping reports users can move on to other Att&ck activities, including:
CISA said it welcomes feedback from the cybersecurity community, bug reports and feature suggestions.