This commit is contained in:
patel-bhavin
2021-08-31 12:54:56 -07:00
parent 7f8a3bebb6
commit 542a841ad7
+1
View File
@@ -55,3 +55,4 @@ To view an up-to-date detection coverage map for all the content tagged with MIT
If curious about how the Threat Research team prioritizes what content to build refer to our **Detection Priority by Threat Actors** layer in [https://mitremap.splunkresearch.com/](https://mitremap.splunkresearch.com/). Using the actor data from [MITRE CTI](https://github.com/mitre/cti) we add a point for every threat actor that uses a particular technique, and then subtract a point of every detection we have mapped to that technique. The resulting map below is how we prioritize what techniques and detections to focus on next. This map is automatically updated on every release and is generated by the [generate-actors-map.py](https://github.com/splunk/security_content/blob/develop/bin/generate-actors-map.py) script.
![](https://github.com/splunk/security_content/blob/develop/docs/mitre-map/priority.png)