MISP-Maltego visualizes Tropic Trooper ATT&CK gaps
A MISP project blog demonstrates using Maltego visualization to compare ATT&CK techniques between a Cylance report on Tropic Trooper and MITRE's own documentation.
This article is a methodology piece from the MISP Project demonstrating how to use Maltego alongside MISP threat-sharing data to visualize and compare MITRE ATT&CK techniques associated with threat reports. It uses a real-world example: a Cylance report titled 'PcShare Backdoor Attacks Targeting Windows Users with FakeNarrator Malware,' published September 25, 2019, which attributed the activity to the Tropic Trooper actor (MITRE G0081) and documented 16 related ATT&CK techniques.
The author walks through building a graph in Maltego from a MISP event, expanding threat actor galaxies into ATT&CK technique relationships, and using entity clustering to make the resulting graph readable. The analysis reveals that only 5 techniques overlap between the Cylance report and MITRE's documented techniques for Tropic Trooper, with 13 techniques unique to MITRE and 11 unique to the Cylance report — a much larger discrepancy than the naive 2-technique gap initially assumed by comparing raw counts.
The piece is primarily educational, illustrating cognitive limitations in manual intelligence analysis (citing Heuer's working memory research) and advocating for visualization tools to reconcile discrepancies in ATT&CK tagging across sources. It does not describe new malicious activity, but references the pre-existing Tropic Trooper/PcShare campaign as a case study.
Mentioned in this report
Source reporting: https://www.misp-project.org/2019/10/27/visualising_common_patterns_attack.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free