Abstract
Understanding the potential impact of a vulnerability requires more than simply identifying the issue; it involves determining what an adversary could realistically achieve by exploiting it.While frameworks like MITRE ATT&CK formalize adversary tactics, techniques, and procedures (TTPs), connecting concrete security issues to actionable TTPs remains limited. Existing approaches offer only partial solutions: some rely exclusively on static relations, while others are restricted to isolated mappings between frameworks (e.g., CVE → CWE). However, none provide a practical, end-to-end integration of both static and dynamic mappings across the threat intelligence landscape.To address this gap, we introduce ThreatCompass: the first open-source system that automatically identifies security issues, maps them to relevant TTPs using a combination of static knowledge and machine learning techniques, and visualizes the resulting attack graph to support security analysts in actionable decision-making.
Cite
CITATION STYLE
Krijnen, Y. A., Simonetto, S., Oostveen, R., Bosch, P., & Jonker, W. (2025). ThreatCompass: A Tool for Identifying and Mapping Security Issues to TTPs. In LAMPS 2025 - Proceedings of the 2nd ACM Workshop on Large AI Systems and Models with Privacy and Security Analysis (pp. 58–67). Association for Computing Machinery, Inc. https://doi.org/10.1145/3733800.3763265
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.