pwnsy
Runs on your device

MITRE ATT&CK Evidence Mapper

Paste incident notes, log lines or command lines and see which MITRE ATT&CK techniques they point to, with the phrases that matched, the tactics still missing evidence and every indicator in the text.

Samples

Tactic coverage

tap a tactic to filter

Techniques

Paste evidence or load a sample.

How the ATT&CK mapper works

The mapper holds 80 rules, one per MITRE ATT&CK Enterprise technique or sub-technique, each with a list of phrases and a weight. Your text is split into lines and every phrase is matched on word boundaries, so "iex" does not match "review" while ".lnk" and "admin$" still match.

  • Score = phrases matched × technique weight. High is 10 or more, medium 5 to 9, low below 5.
  • Tactics: techniques that span several tactics are filed under their most common one, across the 14 Enterprise tactics.
  • Collect next lists the evidence gaps: missing tactics such as initial access or persistence, and follow-ups such as resetting dumped credentials.
  • Indicators are pulled out with patterns for URLs, domains, IPs, emails, hashes, CVEs, file paths and registry keys.

How to read the result

The heatmap colours each tactic by its best match: dark green for high confidence, mid green for medium, pale for low, grey for none. Open a technique to see the score sum and the lines that matched, with each phrase highlighted. Confidence reflects matched text only and makes no attribution claim, so validate each technique against primary telemetry before you report it.

ATT&CK mapper FAQ

Are my notes sent anywhere?

No. The rules, the scoring and the indicator extraction all run in this page. Your notes are not uploaded and are not saved in the browser, so they are gone when you close the tab.

How is confidence scored?

Each technique has a list of phrases and a weight. The score is the number of its phrases found in your notes times the weight. A score of 10 or more is high, 5 to 9 is medium and below 5 is low.

Can I correct a mapping?

Yes. Each technique has a confidence menu. Set it to high, medium or low, or exclude it. The heatmap, the report, the CSV and the Navigator layer all follow your choice.

How do I open the Navigator layer?

Download the layer, open MITRE's ATT&CK Navigator, choose Open Existing Layer and then Upload from local. Techniques are scored 1 for low, 2 for medium and 3 for high confidence.

Which indicators does it extract?

URLs, domains, IPv4 and IPv6 addresses, email addresses, SHA256, SHA1 and MD5 hashes, CVE IDs, file paths and registry keys. Defanged values such as hxxp and [.] are refanged first.

Triage only. Validate against primary telemetry before reporting.

Report copied