ThreatCompass: A Tool for Identifying and Mapping Security Issues to TTPs

0Citations
Citations of this article
18Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Understanding the potential impact of a vulnerability requires more than simply identifying the issue; it involves determining what an adversary could realistically achieve by exploiting it.While frameworks like MITRE ATT&CK formalize adversary tactics, techniques, and procedures (TTPs), connecting concrete security issues to actionable TTPs remains limited. Existing approaches offer only partial solutions: some rely exclusively on static relations, while others are restricted to isolated mappings between frameworks (e.g., CVE → CWE). However, none provide a practical, end-to-end integration of both static and dynamic mappings across the threat intelligence landscape.To address this gap, we introduce ThreatCompass: the first open-source system that automatically identifies security issues, maps them to relevant TTPs using a combination of static knowledge and machine learning techniques, and visualizes the resulting attack graph to support security analysts in actionable decision-making.

Cite

CITATION STYLE

APA

Krijnen, Y. A., Simonetto, S., Oostveen, R., Bosch, P., & Jonker, W. (2025). ThreatCompass: A Tool for Identifying and Mapping Security Issues to TTPs. In LAMPS 2025 - Proceedings of the 2nd ACM Workshop on Large AI Systems and Models with Privacy and Security Analysis (pp. 58–67). Association for Computing Machinery, Inc. https://doi.org/10.1145/3733800.3763265

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free