live
MITRE ATT&CK Chain Visualizer
Groups Atomic Red Team telemetry into parent–child process chains and scores multi-stage ATT&CK sequences with explainable confidence.
- Cybersecurity
- MITRE
- Visualization
- EDR
Overview
MITRE ATT&CK Chain Visualizer ingests Atomic Red Team Sysmon, Falcon, and PowerShell telemetry, groups events into parent–child process chains via union-find and time-window linking, and scores multi-stage sequences (Execution → Credential Access → Persistence) with explainable rule-based confidence. An analyst-facing Streamlit dashboard offers confidence, length, and tactic filters plus Plotly timelines — default ≥40% confidence and multi-event gating reduce triage noise across 12K+ events / 11K+ chains.
Highlights
- Process-chain grouping via union-find and time-window linking
- Multi-stage ATT&CK sequence scoring with explainable confidence
- Plotly timelines with cmdline and explanation hovers
- Triage filters that cut noise across 12K+ events