Skip to main content

Threat Intelligence

CVE to ATT&CK

CVE to MITRE ATT&CK Mapping

Every vulnerability read as adversary behavior.

An AI assisted mapping reads each CVE in ATIP into MITRE ATT&CK in two steps, the tactic first and then the techniques under it, so a finding can be discussed as what an attacker would do with it, not only how severe it scored.

From a CVE number to MITRE TTPs

The mapping is produced in a multi-stage Avint threat intelligence pipeline with AI assistance. A CVE's description is leveraged to map it to the official tactic and technique lists with high coverage and accuracy. The result lands on the CVE record inside ATIP, next to the actors, malware and exploit context for the same vulnerability. It is one of the enrichments that make the feed more than a list of CVEs, and inside AlloyGRC it appears wherever a CVE is discussed: the ATIP lookup, vulnerability views and risk narratives.

A CVSS score says how bad. A technique says what for.

How it works

How a CVE becomes a tactic and its techniques

The stages the mapping runs, from start to finish

STAGE 01

Data Preparation

CVEs are ingested along with their description, enriched with additional information like CWE and CVSS, and normalized.

Clean, un-mapped data ready for mapping

STAGE 02

LLM-based Ranking

On-Prem LLMs use ingested TTP documentation to rank and predict tactics and techniques

Ranked list of TTP candidates for every CVE.

STAGE 03

Sanity Check

Shortlisted candidates are put through contradiction and pattern-based filters to narrow down potential mappings.

Narrowed-down, highly explainable candidate pool

STAGE 04

Composite Scoring

Multiple factors including LLM rankings, contradictions and bonuses are used to determine the final tactic and technique mappings.

Standardized, explainable, and accurate TTP mappings for ingested CVEs

What you can do

  • Check the tactics and techniques on a CVE before writing a risk narrative

  • Use technique context to justify a remediation priority that CVSS alone would rank lower

  • Connect a finding to the adversary behavior an assessor or a leader will recognize

Straight answers

Is every CVE mapped?

Most of the corpus carries at least one tactic. A CVE with no known association shows none rather than a guess.

Why does a CVE sometimes show a tactic but no technique?

Because the mapping runs in that order. The tactic is assigned first, and techniques are attached where the evidence supports a specific one. A CVE with a tactic and no technique is reported that way rather than guessed.

CVE to MITRE ATT&CK Mapping has more to show than fits on this page yet. A full walkthrough with visuals is being written. Ask for a demo to see it running today.

See a CVE the way an adversary would use it.

Bring a CVE you care about to the demo and we will walk through its context end to end.