A library management system within Elastic Security for creating, organizing, and managing detection rules, exceptions, and threat intellige...
MITRE ATT&CK Navigator
MITRE ATT&CK Navigator is a free web-based tool for visualizing, annotating, and comparing coverage of adversary tactics and techniques from the MITRE ATT&CK knowledge base.
Threat Detection
open-source
mitre-attack
detection-engineering
purple-team
Overview
MITRE ATT&CK Navigator is a free, open-source web application developed by MITRE for exploring, annotating, and comparing coverage of adversary tactics and techniques documented in the ATT&CK knowledge base. Analysts use the Navigator to build heatmaps that show which techniques an organization's detection rules, threat intelligence reports, or red team activity covers. Layers can be created manually, imported from ATT&CK data, or generated by tools such as ATT&CK Workbench and Atomic Red Team. The Navigator supports Enterprise, Mobile, and ICS matrices, and layers can be exported as JSON for sharing or version control. It is widely used in detection engineering, purple team exercises, gap analysis, and security program reporting, and it can be self-hosted or used via the hosted version.
Primary Use Cases
✔
Visualizing detection coverage as heatmaps mapped to the MITRE ATT&CK Enterprise, Mobile, or ICS matrices to identify defensive gaps.
✔
Mapping threat intelligence reports and adversary group behavior to specific ATT&CK techniques for contextualized threat modeling.
✔
Planning and reporting purple team exercises by comparing red team activity layers against blue team detection layers in a single view.
Frequently Asked Questions
Metadata
Official Website
Visit Website
Category Info
Threat Detection covers tools and frameworks used to design, organize, visualize, and validate detection coverage against known adversary tactics, techniques, and procedures.
Added On
September 16, 2026
Last Updated
September 16, 2026
Related Security & OSINT Tools
Threat Detection
Threat Detection
A powerful library manager for Sigma detection rules, supporting validation, conversion to SIEM queries, and rule organization for enterpris...
Endpoint Security
Fail2Ban is a lightweight open-source intrusion prevention tool that monitors log files and dynamically bans IP addresses showing malicious ...