Launch Day: ASS3T is here!

Last year I started playing around with PowerBI, a pretty nifty data analytics and visualisation tool from Microsoft. It’s a pretty straightforward and simple application to get the hang of too, which is great for people who aren’t data analysts by trade (like myself).

If you’ve seen some of my recent posts here on LinkedIn, you’ll know I love talking about threat-informed defence and frameworks, often featuring MITRE ATT&CK.

Anyway, I’ve recently finished building a template in PowerBI called ASS3T, or Advanced Security Selection and Evaluation Tool.

Using ASS3T you can quickly and easily explore the MITRE ATT&CK framework, filtering techniques by attack objective (tactics) and identify the corresponding mitigations (controls) across Enterprise, Industrial Control Systems (ICS) and Mobile technology domains.

I’ve made a few updates to the tool since ATT&CK version 15 was released earlier this year. 

  • Added a threat actor dashboard for multi-stage attack analysis and discovery.

  • Added a platform dashboard to filter techniques by tech stack/platform.

  • Added a control effectiveness score (CES) to identify which mitigations cover the most attack techniques

Today, I’m excited to release ASS3T into the wild for the benefit of the broader cyber community.

Head over to my resources page (see top) to grab a copy!

As always, thoughts, ideas and feedback are welcome. Let me know what you think in the comments. 

I will be making some updates to the template in future. So make sure you subscribe to stay in the know!

If you like the tool and get some value out of it, I’d really appreciate it if you could ‘buy me a coffee’ to help support my work! https://buymeacoffee.com/jasonlayton

Thanks!

Previous
Previous

Cyber Threat Knowledge vs. Cyber Threat Action

Next
Next

Disrupting Nation-State Hackers