Using MITRE ATT&CK Navigator to Strengthen Threat Modelling [PART: II]

Using MITRE ATT&CK Navigator to Strengthen Threat Modelling [PART: II]

Views: 4

๐ŸŽฏ A Hands-On, Step-by-Step Walkthrough

ATT&CK
Tool

๐Ÿ“š 1. Why Map a Threat Group at All?

A threat model that stops at “we might get hacked” is not much use. ATT&CK lets you say something far more specific: “this group tends to gain initial access this way, move laterally that way, and these are the techniques we can’t currently detect.”

The Navigator turns that knowledge into a visual matrix you can colour, score, comment on, and share. Mapping a group takes four moves:

  1. ๐Ÿงฑ Create a layer
  2. ๐Ÿ” Search and select the group’s techniques
  3. ๐Ÿงฎ View, sort and filter the matrix
  4. ๐Ÿ–๏ธ Annotate with colours, scores, comments, links and metadata

๐Ÿงฐ 2. Prerequisites

  • A running ATT&CK Navigator instance (mine is self-hosted in my lab)
  • A browser
  • 20 minutes โ˜•

Optional: spin up your own Navigator

If you don’t have an instance yet, you can run the open-source Navigator locally. Check the project README for the current Node/Angular requirements, as they change between releases.

git clone https://github.com/mitre-attack/attack-navigator.git
cd attack-navigator/nav-app
npm install
npx ng serve --host 0.0.0.0
# then browse to http://<your-host>:4200

โš ๏ธ Keep the Navigator version consistent when you compare results across machines or colleagues. Technique counts and group-to-technique mappings change between ATT&CK versions, so a layer built on one version can look different on another.


๐Ÿš€ 3. Mapping APT41

Who is APT41?

APT41 is tracked in ATT&CK as group G0096. It is widely known for blending state-sponsored espionage with financially motivated intrusions, and it is also tracked under other names such as Wicked Panda and Brass Typhoon. Open the group’s page in ATT&CK to see the current alias list and the techniques it is linked to.

๐Ÿ’ก Why this group is a good exercise: its behaviour spans the whole kill chain, from internet-facing exploitation and supply-chain compromise to credential theft and data collection. That makes it a good test of whether every column of your matrix means something to you.

๐ŸŸฆ Step 1: Open the Navigator landing page

Browse to your instance (e.g. http://<your-navigator-host>:4200) or use the one hosted in Github https://mitre-attack.github.io/attack-navigator/. The landing page gives you four options:

OptionWhat it does
Create New LayerStart from an empty matrix
Open Existing LayerLoad a saved layer from a file or URL
Create Layer from Other LayersMerge or inherit properties from layers you already have
Create Customized NavigatorGenerate a hyperlink to a pre-configured Navigator

The Landing page of the MITRE ATT&CK Navigator.


๐ŸŸฉ Step 2: Create a new Enterprise layer

  1. Click Create New Layer.
  2. Choose one of the three domains:
    • Enterprise: techniques used against enterprise networks (Windows, Linux, macOS, cloud, SaaS)
    • Mobile: techniques targeting phones and tablets
    • ICS: techniques targeting industrial control systems
  3. Pick Enterprise. APT41 operates mainly against enterprise environments, so this is where it lives.
  4. If you need a specific ATT&CK version, expand More Options first and choose it there.

You should now see the full matrix, with tactic columns running left to right: Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact.


๐ŸŸช Step 3: Find APT41 with the Selection Controls

One of the most powerful tools on offer is the search menu, which allows you to see a list of APTs, malware, mitigations, and even some specific attacks, referred to as โ€œCampaignsโ€.ย 

  1. In the toolbar, find the Selection Controls group (lock, magnifier, and deselect icons).
  2. Click the magnifier ๐Ÿ”. A search panel opens on the right.
  3. Type APT41 into the search box.

The panel lists matches under six headings:

  • Techniques
  • Threat Groups
  • Software
  • Mitigations
  • Campaigns
  • Data Sources

You can also adjust the Search Settings (name, ATT&CK ID, description, data sources) to control what the search looks at.

๐Ÿง  Watch out: a search for APT41 may return more than one entry under Threat Groups, because another group’s description can mention APT41. In my case I made sure I picked the APT41 entry itself rather than a similar-looking one. Always check the name before you click.


๐ŸŸง Step 4: Preview, then select the group’s techniques

  1. Under Threat Groups, hover over the APT41 entry. Every technique linked to that group lights up in the matrix. This is a free preview, and nothing is committed yet.
  2. Click select next to APT41.

The highlighted techniques are now a selection that you can annotate as a block.

  1. Look at the deselect (โœ•) button in the Selection Controls. It now shows a number, which is how many techniques are currently selected. Hover over it to see the tooltip (for example, “deselect N techniques”).

๐Ÿ“ Write that number down. It will differ between ATT&CK versions.


๐ŸŸฅ Step 5: Fine-tune with right-click

Sometimes you need to adjust one technique, not the whole group. Right-click any technique to open the context menu:

Menu itemUse it toโ€ฆ
select / add to selection / remove from selectionChange the selection one technique at a time
select all / deselect all / invert selectionBulk operations
select annotated / select unannotatedWork only on techniques you have (or haven’t) annotated
select all / deselect all techniques in tacticAct on a whole column
view technique / view tacticOpen the official ATT&CK page
pin / unpin tooltipKeep the technique tooltip on screen

๐ŸŸฆ Step 6: View, sort and filter with the Layer Controls

The Layer Controls group is where you shape what you see. Four features matter most for this exercise.

You can define a custom name for the Layer from Layer Controls –> Layer Settings,

6.1 ๐Ÿ“ค Export

Download the layer as JSON, Excel, or SVG. The JSON can be re-imported into any Navigator later, and the SVG is ideal for reports and slides. (More in Step 9.)

6.2 ๐Ÿงช Filters

Filter the matrix by platform. The options include Linux, macOS, Windows, Network, PRE, Containers, Office 365, SaaS, Google Workspace, IaaS and Azure AD.

Try this as an experiment:

  1. Open the filter dropdown.
  2. Tick Windows only. Note how the matrix shrinks to what applies to your estate.
  3. Switch to IaaS and see what remains. Record the count under a tactic that matters to you, such as Discovery.

This is the quickest way to answer “which of APT41’s techniques actually apply to my platforms?”

Windows:

IaaS:

6.3 ๐Ÿ”ค Sorting

Sort the techniques alphabetically (ascending or descending), or by score once you have scored them. Hover over the icon to see which sort mode is active.

6.4 ๐ŸŒณ Expand sub-techniques

Click expand sub-techniques to reveal everything beneath each technique, for example the specific interpreters under Command and Scripting Interpreter. Click it again to collapse. Sub-technique level is where detection engineering usually happens, so expand before you start scoring.


๐Ÿ–๏ธ Step 7: Annotate with the Technique Controls

Now the fun part. With APT41’s techniques still selected, use the Technique Controls panel. From left to right:

IconControlWhat to do with it
โ–จToggle stateGrey out techniques that don’t apply to you
๐ŸชฃBackground colourGroup and prioritise visually
๐Ÿ“ŠScoringRate impact, likelihood, or coverage
๐Ÿ’ฌCommentAdd notes and observations
๐Ÿ”—LinkAttach references (reports, tickets, detection rules)
๐Ÿ“‹MetadataAdd custom tags and labels
๐ŸงนClear annotations on selectedReset if you change your mind

7.1 โฌœ Toggle state (disable what’s out of scope)

Select the techniques that can’t apply to your environment and click toggle state. They turn grey and no longer distract you.

7.2 ๐ŸŽจ Colour Setup

Select a group of techniques, click the paint bucket, and pick a colour from the palette.

Let us map the TTPs of APT41 using the “Backgroung Colour” option under the “Technique Controls”.

Alternatively, we can use the Color setup in Layer Controls in combination with the Scoring (refer 7,3) to apply colours based on Scores (low to high). This is the most useful method for most of the use cases.

7.3 ๐Ÿ“Š Scoring

A score is a numeric value assigned to a technique. The meaning or interpretation of scores is completely up to the user user – the Navigator simply visualizes the matrix based on any scores you have assigned. Some possible uses of scores include:

  • Assigning a score to techniques based on whether a given adversary group has been observed to use that technique.
  • Assigning a score to techniques based on your organization’s ability to detect, prevent and/or mitigate the use of a particular technique.
  • Assigning a score to those techniques that a red-team has successfully employed during an exercise.

By default, techniques are “unscored” meaning that no score has been assigned to the technique. Note that “unscored” and a score of zero are not the same, specifically with respect to automatically assigned colors. 

Let’s take our APT41 example and explore two possible use cases.

7.3.1 ๐Ÿ“Š USE CASE: Comparing two Threat Groups

Step 1: Create Layer 1 (Threat Group A)

  1. Open the MITRE ATT&CK Navigator.
  2. Click Create New Layer -> select Enterprise.
  3. Click the Selection button (magnifying glass) in the toolbar. Search for your first threat group (e.g., APT41) under the Threat Groups dropdown and click Select.
  4. Click the Score button (coin icon) and assign these techniques a score of 1.
  5. In the Layer Settings (gear icon), change the layer name to Group_A. Note its tab identifier at the top of your browser (usually a). [1, 2, 3, 4, 5]

Color Setup used for Group_A in Layer Control:

Step 2: Create Layer 2 (Threat Group B)

  1. Click the + icon at the top of the Navigator to open a new tab.
  2. Click Create New Layer -> select Enterprise.
  3. Open the Selection menu, search for your second threat group (e.g., APT29), and click Select.
  4. Click the Score button and assign these techniques a score of 2.
  5. Change the layer name to Group_B. Note its tab identifier (usually b). [1, 2, 3, 4]

Color Setup used for Group_B in Layer Control:

Step 3: Combine and Overlap the Groups

  1. Click the + icon to open a new tab.
  2. Select Create Layer from Expression.
  3. In the score expression field, type: a + b.
  4. Click Create. [1, 2, 3]


Step 4: Interpret the Numerical Results

Your combined matrix will display individual technique boxes populated with computed values. The math maps out their shared and distinct characteristics: [1]

Resulting ScoreThreat Intelligence MeaningAnalytical Explanation & Takeaway
0Unused by either actor.Not relevant to this specific comparative threat profile.
1Unique to Group A only.TTPs exclusive to Group A. Focus on these if you are specifically targeted by Group A rather than Group B.
2Unique to Group B only.TTPs exclusive to Group B. Represents the distinct operational signature of the second actor.
3Shared Overlap (Both Groups).High-Priority Synergy. TTPs utilized by both actors. Defending against these yields the highest ROI for your SOC.

Step 5: Color-Code the Matrix View

To translate these numbers into an immediate, presentation-ready visual: [1, 2]

  1. In the combined layer, click the Color Setup button (paint palette). [1]
  2. Set the Min value to 1 and the Max value to 3. [1, 2]
  3. Modify the gradient color stops to assign highly distinct shades:
    • Score 1 (Group A only) โ†’ Red
    • Score 2 (Group B only) โ†’ Green
    • Score 3 (Shared Overlap) โ†’ Blue

Interpret the Calculated Results


Resulting ScoreBehavioral MeaningThreat Intelligence Profile & Focus
Score 1 (Red)Group_A OnlyStealth, Cloud, & Identity Dominance. Reflects focus on stealthy supply-chain compromises (e.g., SolarWinds), heavy targeting of Microsoft 365/Azure environment tokens, and quiet operational infrastructure.
Score 2 (Green)Group_B OnlySoftware Exploitation & Dual-Motivations. Reflects aggressive weaponization of zero-day vulnerabilities (e.g., Log4j), extensive use of custom ransomware/crypto-mining for personal financial gain, and massive software supply-chain compromises (e.g., ASUS).
Score 3 (Blue)Shared OverlapThe Enterprise Baseline. Both groups rely heavily on core system utilities like PowerShell (T1059.001), Valid Accounts (T1078), and web-service exfiltration.

Executive Summary of the Results:

When explaining this map to your leadership or security operations team, present the data using these three core threat intelligence conclusions:

1. The Blue Cells (Score 3) = Your High-ROI Detection Baseline

The overlap cells demonstrate that despite having entirely different geopolitical objectives, both groups utilize identical fundamental mechanics once inside a network. They rely heavily on Living off the Land (LotL) techniques. Prioritizing detections for OS Credential Dumping (T1003) or Process Injection (T1055) provides dual-value protection against both actors simultaneously. [1, 2, 3, 4]

2. The Red Cells (Score 1) = The Identity & Cloud Challenge (APT41)

Group_A’s signature is identity-centric. They excel at compromising authentication mechanisms rather than spamming noisy exploits. If your organization is a government agency, think tank, or high-value policy target, the Blue cells tell you that your defenses must focus on OAuth token abuse, identity provider logging, and anomalous cross-tenant cloud activity. [1, 2, 3]

3. The Yellow Cells (Score 2) = The Edge Infrastructure Challenge (APT29)

Group_B is historically aggressive with perimeter exploitation. Their signature involves mass-scanning public-facing infrastructure to drop web shells. Furthermore, because they operate both state-sponsored espionage and rogue financial cybercrime operations, their toolset is vast and includes custom malware strains. The Yellow cells tell you that defense requires strict external attack surface management, rapid patch deployment pipelines, and endpoint isolation capabilities.

7.4 ๐Ÿ’ฌ Comments

Hover over a technique to see its tooltip, which shows the technique name and ID, its score, and your comment. Write comments that your future self can act on. For example:

“Internet-facing web app is in scope. Patch cadence is monthly, so exposure window is up to 30 days. WAF in detect-only mode.”

7.5 ๐Ÿ”— Links

Add a label and a URL so the technique points to something useful: the vendor advisory, an internal runbook, a detection rule, or the ATT&CK page itself. You can add several links to one technique and remove them individually.

7.6 ๐Ÿ“‹ Metadata

Add key/value tags. Good candidates:

NameExample value
ownerSOC / Infra / AppSec
assetcustomer-db
detection-statusnone / partial / tested
ticketSEC-1234

๐Ÿ“ธ SNAPSHOT 9: Technique tooltip showing score and comment, plus the link dialog ![Annotation tooltip and link dialog](images/09-annotations.png)



๐Ÿ’พ Step 8: Export and reuse your layer

From the Layer Controls, export:

FormatBest for
JSONSaving your work and re-importing it later (all annotations included)
ExcelSharing with managers and auditors, and filtering in a spreadsheet
SVGPasting a crisp image into reports, slides and blog posts

To reload a layer later, use Open Existing Layer on the landing page and load the JSON file.

๐Ÿ—‚๏ธ Housekeeping tip: name files with the group, date and ATT&CK version, e.g. apt41_2026-10_enterprise.json. Versions matter when you compare layers over time.

Exported as SVG:

Group_B:


๐Ÿงฎ 4. Turning the Map Into a Decision

A coloured matrix is only useful if it changes what you do next. Take your red and orange cells and build a short priority table:

#Technique (ID)TacticWhy it matters hereScoreNext action
1e.g. Exploit Public-Facing Application (T1190)Initial AccessInternet-facing services in scope5Patch SLA, WAF in block mode
2your pick
3your pick
4your pick

For each row, open the technique’s ATT&CK page and read the Mitigations and Detection sections. They tell you what controls to apply and which logs to collect, which is exactly the input a threat model needs.

How to prioritise

  • ๐Ÿฅ‡ Initial Access and Execution first. Stopping the attacker early shrinks everything downstream.
  • ๐Ÿฅˆ Credential Access and Privilege Escalation next. These decide whether a foothold becomes a breach.
  • ๐Ÿฅ‰ Then Collection, Exfiltration and Impact, guided by your most critical assets (customer data, transaction records, PII, intellectual property).
  • ๐Ÿ” Don’t forget availability. A technique that doesn’t touch your data can still hurt you if it takes services down.

โš ๏ธ 5. Common Pitfalls

  1. Treating the map as a checklist of everything the group has ever done. ATT&CK lists documented behaviour. Absence of a technique is not proof the group can’t use it.
  2. Mixing ATT&CK versions. Counts and mappings shift between releases. Record the version in your file name.
  3. Selecting the wrong threat group entry. Always check the name before clicking select.
  4. Colouring without a legend. If it isn’t written down, a colleague can’t read your layer. Add the legend as a layer description or as metadata.
  5. Skipping sub-techniques. Detection logic is written at sub-technique level, so expand before you score.
  6. Scoring once and forgetting. Revisit the layer after each control improvement, so your greens are earned.