diff --git a/docs/README.md b/docs/README.md index 8b27943df9..2ad0e8a6a6 100644 --- a/docs/README.md +++ b/docs/README.md @@ -55,3 +55,4 @@ To view an up-to-date detection coverage map for all the content tagged with MIT If curious about how the Threat Research team prioritizes what content to build refer to our **Detection Priority by Threat Actors** layer in [https://mitremap.splunkresearch.com/](https://mitremap.splunkresearch.com/). Using the actor data from [MITRE CTI](https://github.com/mitre/cti) we add a point for every threat actor that uses a particular technique, and then subtract a point of every detection we have mapped to that technique. The resulting map below is how we prioritize what techniques and detections to focus on next. This map is automatically updated on every release and is generated by the [generate-actors-map.py](https://github.com/splunk/security_content/blob/develop/bin/generate-actors-map.py) script. ![](https://github.com/splunk/security_content/blob/develop/docs/mitre-map/priority.png) +