PR
precize/iran-apt-mitre-attack-matrix
Tactics and Techniques used by Iraninan APT groups for MITRE
Precize - Iran-Linked MITRE ATT&CK Enterprise Matrix
What it contains
index.html- external-facing static siteassets/- site CSS and JavaScriptdata/generated_layers/*.json- one per-group Navigator layer generated from MITRE ATT&CK Excel mappingsdata/iran_attack_aggregated_layer.json- combined Navigator layer across all selected groupsdata/manifest.json- full machine-readable dataset used by the sitedata/validation.json- validation summarydata/enterprise-attack-v18.1-groups.xlsx- MITRE ATT&CK source filedata/enterprise-attack-v18.1-techniques.xlsx- MITRE ATT&CK source filedata/enterprise-attack-v18.1-tactics.xlsx- MITRE ATT&CK source filescripts/build_repo.py- regeneration script
Build logic
This repository uses MITRE ATT&CK Excel v18.1 files from the official ATT&CK Data & Tools page.
- Group descriptions are taken from
groups.xlsx. - Group-to-technique mappings are taken from
groups.xlsx→techniques used. - Technique names, URLs, tactics, and platforms are taken from
techniques.xlsx. - Per-group local layer files are generated in
data/generated_layers/. - The combined layer in
data/iran_attack_aggregated_layer.jsonscores each technique by the number of selected groups that use it.
Selected group IDs
Group IDs and names
- G1030 Agrius
- G0130 Ajax Security Team
- G0064 APT33
- G0087 APT39
- G1044 APT42
- G0003 Cleaver
- G0052 CopyKittens
- G1012 CURIUM
- G1027 CyberAv3ngers
- G0137 Ferocious Kitten
- G0117 Fox Kitten
- G0043 Group5
- G0077 Leafminer
- G0059 Magic Hound
- G1009 Moses Staff
- G0069 MuddyWater
- G0049 OilRig
- G0122 Silent Librarian
Open the combined matrix in ATT&CK Navigator
- Go to the MITRE ATT&CK Navigator https://mitre-attack.github.io/attack-navigator/
- Choose Open Existing Layer.
- Upload
data/iran_attack_aggregated_layer.jsonor point to https://github.com/precize/precize-iran-mitre-matrix/blob/main/data/iran_attack_aggregated_layer.json
Notes
- The repository keeps the original MITRE Excel source files so external reviewers can reproduce the build.
- The per-group JSON files are generated locally from those MITRE mappings. They are intended for GitHub sharing and ATT&CK Navigator loading.
On this page
Languages
Python68.9%JavaScript12.8%CSS10.5%HTML7.8%
Contributors
Apache License 2.0
Created March 13, 2026
Updated March 17, 2026