{% comment %} _includes/ttp-overlap-diagram.html ────────────────────────────────────────────────────────────────────── Renders a Kaspersky-style TTP overlap flow diagram showing which ransomware groups / infostealer families share each MITRE technique. Requires page.ttp_data_key to be set (e.g. "ransomware_ttp_overlap"). Data is read from site.data[page.ttp_data_key]. The SVG is rendered client-side by assets/js/ttp-overlap.js using window.TTP_OVERLAP_DATA injected below. {% endcomment %} {% assign ttp_data = site.data[page.ttp_data_key] %} {% if ttp_data %}
Each box represents a MITRE ATT&CK technique. Colored dots indicate which groups or families use that technique - techniques where all dots are filled are universal chokepoints and the highest-value targets for detection engineering. Hover or focus a technique for detail.