logo

McAfee ATR Thinks in Graphs

ID: 39a4e58a-cce4-59b0-990a-8d522bb41f11

STIX ID: report--39a4e58a-cce4-59b0-990a-8d522bb41f11

Feed Name: McAfee Labs Blog

Date Published: 2021-03-08

Date Updated: 2026-04-28

Author: Valentine Mairet

...
...

This paper from McAfee Advanced Threat Research presents a methodology for transforming large, historical MISP-based threat intelligence into event-centric and actor-centric graphs to analyze MITRE ATT&CK technique usage and actor behavior. Using degree, centrality, and Louvain clustering, the study identifies frequently observed techniques and prominent actors while revealing dense overlaps that limit differentiation due to data sparsity and missing kill chain step granularity. The authors discuss limitations of their tooling and dataset, note the challenges of distinguishing actors that use similar techniques, and outline future work to incorporate EDR-derived context, targeted (non–crimeware) campaigns, and external sources like Intezer to enhance graph granularity and analytic value.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.