
A Python package to interact with the Mitre ATT&CK Framework
.______ ____ ____ ___ .___________.___________. ______ __ ___
| _ \ \ \ / / / \ | | | / || |/ /
| |_) | \ \/ / / ^ \ `---| |----`---| |----`| ,----'| ' /
| ___/ \_ _/ / /_\ \ | | | | | | | <
| | | | / _____ \ | | | | | `----.| . \
| _| |__| /__/ \__\ |__| |__| \______||__|\__\
A Python package to interact with MITRE ATT&CK Frameworks
Current Version is 7.1.1
pyattck is a light-weight framework for MITRE ATT&CK Frameworks. This package extracts details from the MITRE Enterprise, PRE-ATT&CK, Mobile, and ICS Frameworks.
pyattck assist organizations and individuals with accessing MITRE ATT&CK Framework(s) in a programmatic way. Meaning, you can access all defined actors, malwares, mitigations, tactics, techniques, and tools defined by the Enterprise, Mobile, Pre-Attck, and ICS frameworks via a command-line utility or embedding into your own code base.
There are many reasons why you would want to access this data in an automated (scripted/coded) way but a few examples are:
There are other benefits that pyattck provide as well which includes the ability to provide additional contextual data. You can find more information about this data here but the basics are that pyattck utilizes multiple open-source repositories to gather additional contextual data like commands used to execute a technique, country and other details about a malicious actor, other variants of malware similar to a defined tool/malware, etc.
This additional context is what makes pyattck truly powerful and enables people to build more robust testing and validation of their detection rules, validates testing assumptions, etc. Truly there are countless ways that pyattck could be utilized to help blue, red, and purple teams defend organizations (and themselves).
The pyattck package retrieves all Tactics, Techniques, Actors, Malware, Tools, and Mitigations from the MITRE ATT&CK Frameworks as well as any defined relationships within the MITRE ATT&CK dataset (including sub-techniques).
In addition, Techniques, Actors, and Tools (if applicable) now have collected data from third-party resources that are accessible via different properties. For more detailed information about these features, see External Datasets.
The pyattck package allows you to:
You can install pyattck on OS X, Linux, or Windows. You can also install it directly from the source. To install, see the commands under the relevant operating system heading, below.
pip install pyattck
git clone https://github.com/swimlane/pyattck.git
cd pyattck
python setup.py install
To use pyattck you must instantiate an Attck object. Although you can interact directly with each class, the intended use is through a Attck object:
from pyattck import Attck
attack = Attck()
By default, sub-techniques are accessible under each technique object. You can turn this behavior off by passing nested_techniques=False when creating your Attck object.
As an example, the default behavior looks like the following example:
from pyattck import Attck
attack = Attck()
for technique in attack.enterprise.techniques:
print(technique.id)
print(technique.name)
for subtechnique in technique.techniques:
print(subtechnique.id)
print(subtechnique.name)
You can access the following main properties on your Attck object:
Once you specify the MITRE ATT&CK Framework, you can access additional properties.
Here are the accessible objects under the Enterprise property:
For more information on object types under the enterprise property, see Enterprise.
Here are the accessible objects under the PreAttck property:
For more information on object types under the preattck property, see PreAttck.
Here are the accessible objects under the Mobile property:
For more information on object types under the mobile property, see Mobile.
Here are the accessible objects under the ICS property: