MITRE ATT&CK Evidence Mapper
Paste incident notes, log lines or command lines and see which MITRE ATT&CK techniques they point to, with the phrases that matched, the tactics still missing evidence and every indicator in the text.
Tactic coverage
tap a tactic to filterTechniques
How the ATT&CK mapper works
The mapper holds 80 rules, one per MITRE ATT&CK Enterprise technique or sub-technique, each with a list of phrases and a weight. Your text is split into lines and every phrase is matched on word boundaries, so "iex" does not match "review" while ".lnk" and "admin$" still match.
- Score = phrases matched × technique weight. High is 10 or more, medium 5 to 9, low below 5.
- Tactics: techniques that span several tactics are filed under their most common one, across the 14 Enterprise tactics.
- Collect next lists the evidence gaps: missing tactics such as initial access or persistence, and follow-ups such as resetting dumped credentials.
- Indicators are pulled out with patterns for URLs, domains, IPs, emails, hashes, CVEs, file paths and registry keys.
How to read the result
The heatmap colours each tactic by its best match: dark green for high confidence, mid green for medium, pale for low, grey for none. Open a technique to see the score sum and the lines that matched, with each phrase highlighted. Confidence reflects matched text only and makes no attribution claim, so validate each technique against primary telemetry before you report it.
ATT&CK mapper FAQ
Are my notes sent anywhere?
No. The rules, the scoring and the indicator extraction all run in this page. Your notes are not uploaded and are not saved in the browser, so they are gone when you close the tab.
How is confidence scored?
Each technique has a list of phrases and a weight. The score is the number of its phrases found in your notes times the weight. A score of 10 or more is high, 5 to 9 is medium and below 5 is low.
Can I correct a mapping?
Yes. Each technique has a confidence menu. Set it to high, medium or low, or exclude it. The heatmap, the report, the CSV and the Navigator layer all follow your choice.
How do I open the Navigator layer?
Download the layer, open MITRE's ATT&CK Navigator, choose Open Existing Layer and then Upload from local. Techniques are scored 1 for low, 2 for medium and 3 for high confidence.
Which indicators does it extract?
URLs, domains, IPv4 and IPv6 addresses, email addresses, SHA256, SHA1 and MD5 hashes, CVE IDs, file paths and registry keys. Defanged values such as hxxp and [.] are refanged first.
Triage only. Validate against primary telemetry before reporting.