INNER CODE UNIT · Python

arg_parse

mitre-attack/attack-scripts · scripts/technique_mappings_to_csv.py:91

def arg_parse():
    """Function to handle script arguments."""
    parser = argparse.ArgumentParser(description="Fetches the current ATT&CK content expressed as STIX2 and creates spreadsheet mapping Techniques with Mitigations, Groups or Software.")
    parser.add_argument("-d", "--domain", type=str, required=True, choices=["enterprise_attack", "mobile_attack"], help="Which ATT&CK domain to use (Enterprise, Mobile).")
    parser.add_argument("-m", "--mapping-type", type=str, required=True, choices=["groups", "mitigations", "software"], help="Which type of object to output mappings for using ATT&CK content.")
    parser.add_argument("-t", "--tactic",  type=str, required=False,  help=" Filter based on this tactic name (e.g. initial-access) " )
    parser.add_argument("-s", "--save", type=str, required=False, help="Save the CSV file with a different filename.")
    return parser


def do_mapping(ds, fieldnames, relationship_type, type_filter, source_name, sorting_keys, tactic=None):
    """Main logic to map techniques to mitigations, groups or software"""
    all_attack_patterns = get_all_techniques(ds, source_name, tactic)
    writable_results = []

    for attack_pattern in tqdm.tqdm(all_attack_patterns, desc="parsing data for techniques"):
        # Grabs relationships for identified techniques
        relationships = filter_for_term_relationships(ds, relationship_type, attack_pattern.id)

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…