← Back to list

How I Use MITRE ATT&CK Navigator

If threat intelligence is about understanding your adversaries, then MITRE ATT&CK Navigator is one of the best tools for making that…

Palupidyahr · 2026-03-04 08:27 · 0 claps · 2.0 min read
#mitre-attack #threat-intelligence #indicators-of-compromise #blue-team #cybersecurity
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

How I Use MITRE ATT&CK Navigator

If threat intelligence is about understanding your adversaries, then MITRE ATT&CK Navigator is one of the best tools for making that understanding visual.

Here’s how I actually use it — not just as a reference, but as a working document.

Starting with the Actors That Matter

Not every threat actor is relevant to every organization. So the first step is being deliberate: I only map TTPs from groups that have a documented history of targeting industries or countries that overlap with where our company operates.

That means actors like APT41 and Lazarus Group naturally end up on the radar — both have conducted campaigns across the APAC region and have shown consistent interest in industries similar to ours. Each actor gets their own dedicated layer, with TTPs defined based on the latest intelligence available.

Merging Layers for a Bigger Picture

Here’s where it gets interesting. Once individual actor layers are built, I use the “Create Layer from Other Layers” feature to combine them.

The result is a unified view — a merged heatmap that shows overlapping techniques across multiple threat actors. This matters because when two or more relevant actors share the same TTPs, those techniques become higher-priority gaps to address. It’s a simple way to move from “here’s what each actor does” to “here’s what we actually need to worry about most.”

From there, it feeds directly into TTP documentation and IOC tracking — turning the visual map into something the team can operationalize.

Layer Merging process

Layer Merging process

Layer Merging result

Layer Merging result

I can also adjust the aggregate scores — controlling how each TTP’s value is calculated across the merged layer. This comes in handy when tailoring the output for different purposes, whether it’s a risk briefing, a detection gap review, or an executive summary. Same data, different framing, different story.

Aggregate Scores settings

Aggregate Scores settings

Taking It Further — Automation

Manual updates don’t scale. So beyond the static mapping work, we’ve also built an automation layer into the process.

Whenever new TTPs are identified, the process updates automatically — our Navigator layers are stored as .json files in an internal folder, so the automation points directly to that file. From there, it's just a matter of uploading through the "Open Existing Layer" import feature, and everything stays current without rebuilding from scratch.


메타데이터
post_id
931c2da520aa
slug
how-i-use-mitre-att-ck-navigator-931c2da520aa
url
https://medium.com/@palupidyahr/how-i-use-mitre-att-ck-navigator-931c2da520aa
canonical_url
https://medium.com/@palupidyahr/how-i-use-mitre-att-ck-navigator-931c2da520aa
author_url
https://medium.com/@palupidyahr
status
ok
fetched_at
2026-07-21 06:15:37