CIRCL/vulnerability-attack-techniques
收藏资源简介:
该数据集将1,207个CVE(通用漏洞披露)映射到MITRE ATT&CK(企业版)技术,结合了MITRE威胁情报防御中心(CTID)手工整理的映射和来自CIRCL/vulnerability-scores的漏洞描述。其目的是训练和评估模型,这些模型可以根据漏洞描述建议候选的ATT&CK技术,帮助防御者了解预期的对手行为和检测方法。数据集包括多个字段:CVE标识符、漏洞标题、英文描述(模型输入)、利用技术、主要影响、次要影响、所有手工技术(训练目标)、CVE2CAPEC派生技术(非训练用)、标签来源和ATT&CK版本。标签来源于CTID的CVE和KEV映射,所有技术ID标准化为企业版ATT&CK v19.1。数据集还包含标签统计、已知限制(如规模较小和选择偏差)和使用示例。上游来源的许可包括Apache-2.0、CC BY 4.0和GPLv3。
This dataset maps 1,207 Common Vulnerabilities and Exposures (CVE) entries to MITRE ATT&CK (Enterprise Edition) techniques, combining manually curated mappings from the MITRE Cyber Threat Intelligence Defense Center (CTID) and vulnerability descriptions sourced from CIRCL/vulnerability-scores. Its purpose is to train and evaluate models that can recommend candidate ATT&CK techniques based on vulnerability descriptions, helping defenders understand expected adversary behaviors and detection methods. The dataset includes multiple fields: CVE identifiers, vulnerability titles, English descriptions (model inputs), exploitation techniques, primary impacts, secondary impacts, all manually curated techniques (training targets), CVE2CAPEC-derived techniques (for non-training use), tag sources, and ATT&CK version. The tags originate from CTID's CVE and KEV mappings, and all technique IDs are standardized to Enterprise Edition ATT&CK v19.1. The dataset also includes tag statistics, known limitations such as small scale and selection bias, and usage examples. The licenses of upstream sources include Apache-2.0, CC BY 4.0, and GPLv3.




