Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature request: filter on ATT&CK data sources #608

Open
RobbeVandenDaele opened this issue Jan 25, 2024 · 2 comments
Open

Feature request: filter on ATT&CK data sources #608

RobbeVandenDaele opened this issue Jan 25, 2024 · 2 comments
Labels
enhancement New feature or request seeking feedback Seeking feedback from the community on this issue

Comments

@RobbeVandenDaele
Copy link

Hi all,

I had an idea which I wanted to share with you. It think it would be a great feature if we can filter the navigator based on the ATT&CK data sources (https://attack.mitre.org/datasources/). This would help a lot in plotting detections on the navigator related to a specific data source, since this removes the clutter of techniques not relevant to a specific data source. I feel like the filters for the platforms are not always sufficient enough.

Kind regards
Robbe

@clemiller
Copy link
Contributor

clemiller commented Jan 25, 2024

Hi @RobbeVandenDaele,

Thank you for opening up this suggestion! I agree that the filtering options in Navigator could be improved and this is an interesting idea. I am leaving this issue open for our team to consider and will mark it as "seeking feedback" in case others in the community have additional thoughts they would like to share.

In the meantime, there are steps you can take to achieve similar functionality. The process for hiding techniques is somewhat involved (related to the improvements requested in #571), but I'm sharing it here in case it is useful to you:

  1. Open the search & multiselect sidebar
  2. Select techniques based on a specific Data Source from the Data Sources panel
  3. Right click a technique in the matrix view and choose "invert selection"
  4. Select "toggle state" under technique controls in the toolbar
  5. Click "show/hide disabled" under layer controls in the toolbar

This will hide all techniques from the view that are not related to the Data Source selected in step 2.

@clemiller clemiller added enhancement New feature or request seeking feedback Seeking feedback from the community on this issue labels Jan 25, 2024
@vynttran
Copy link

Hi @RobbeVandenDaele and @clemiller,

This indeed seems like a useful feature to add! I think we can implement this by adding a ‘data sources’ section in the filters menu (relatively similar to the current ‘platforms’ section, but the toggles in the section will be based on the different data sources).

That said, would it be possible for me to work on this issue? On my team are 3 other friends, @csuraparaju, @tarunBandi-ONE, and @ytw-wyt, who are also excited to help out with implementing this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request seeking feedback Seeking feedback from the community on this issue
Projects
None yet
Development

No branches or pull requests

3 participants