Known Exploited Vulnerabilities mapped to ATT&CK Techniques
收藏资源简介:
The Known Exploited Vulnerabilities (KEV) Catalog is an authoritative source of vulnerabilities exploited in the wild maintained by the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA). Vulnerabilities in the KEV Catalog are contained in the Common Vulnerabilities and Exposures (CVE®) List, which identifies and defines publicly known cybersecurity vulnerabilities. This dataset uses the behaviors described in MITRE ATT&CK® to connect known exploited CVEs to publicly reported methods and impacts of adversary exploitation. Mapped ATT&CK techniques enable defenders to take a threat-informed approach to vulnerability management. With knowledge of mapped adversary behaviors, defenders will better understand how a vulnerability can impact them, helping defenders integrate vulnerability information into their risk models and identify appropriate compensating security controls. This dataset is collected and maintained by MITRE Center for Threat Informed Defense, and made available through their GitHub site.The dataset was labeled using MITRE's CVE Mapping Methodology, archived here. A copy was deposited on Zenodo to ensure long-term preservation and accessibility. The deposited version conforms to ATT&CK Version: 15.1 and covers the ATT&CK Domain: Enterprise



