Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Save timb-machine/393a799e6d6b13a7789133d441280c49 to your computer and use it in GitHub Desktop.
Save timb-machine/393a799e6d6b13a7789133d441280c49 to your computer and use it in GitHub Desktop.
Early implementation of Place in Kill Chain
$ python3 PiKC.py
=== System Parameters Summary ===
System Role: web server
Open Ports: [80, 443, 8080]
IP Addresses: ['203.0.113.50']
Software: Apache httpd 2.4.54
Interactive User: False
Critical Asset: False
Virtualized: False
Internet Facing: True
Has AV/EDR: True
User Account Count: 10
Shares or Mounts: 2
Days Since Last Patch: 120
=== Attack Tactics Prediction ===
Top ATT&CK Tactics: ['Initial Access', 'Command and Control', 'Execution']
Score Breakdown per Tactic:
Initial Access: 5.00
Execution: 2.00
Command and Control: 5.00
Discovery: 2.00
Credential Access: 1.00
Collection: 1.00
Exfiltration: 1.00
Exploitation: 2.00
Not LLM based but the next iteration of automation on our service... inspired by Cisco's Place in Network work...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment