# mitre-attack/attack-navigator

Web app that provides basic navigation and annotation of ATT&CK matrices

Repository: https://github.com/mitre-attack/attack-navigator
Canonical: https://ross.abutalabs.com/products/attack-navigator
Homepage: https://mitre-attack.github.io/attack-navigator
Language: TypeScript
License: Apache-2.0
License Family: permissive
Topics: cti, cyber-threat-intelligence, mitre-attack, mitre-corporation, cybersecurity
Last push: 2026-08-20T20:30:51+00:00

## Health v2 (maintenance only)
Score: 88/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 98, release rhythm 68, longevity 100
- inputs: {"age_days": 3110, "days_push": 13, "days_rel": 134, "gap_med": 80.0, "n_releases_24m": 5}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2448, forks 712 (observed 2026-08-28T04:06:52.804730+00:00)

## What it is
A web application for navigating and annotating MITRE ATT&CK matrices, letting users create custom 'layers' that color-code, comment on, and score techniques. It is client-side only and can be used hosted or self-installed.

## Use cases
- visualize defensive coverage of ATT&CK techniques
- plan red team and blue team engagements against ATT&CK
- map adversary techniques used by a specific threat group
- annotate ATT&CK matrices with scores and comments instead of using Excel
- generate ATT&CK layer files programmatically and view them

## When to choose
- you work with MITRE ATT&CK and need to visualize or annotate matrices
- you want a free, client-side tool with no server-side data storage
- you need to share custom ATT&CK layer views with your team

## When to avoid
- you need automated threat detection or SIEM functionality
- you work with ATT&CK versions older than v4
- you need a full threat intelligence platform rather than a matrix visualization tool

## Facets
- artifact type: application
- maturity: active
- function: data-visualization, developer-tools
- domain: security
- platform: browser, self-hosted
- tags: mitre-attack, threat-intelligence, cti, annotation, typescript, angular, cyber-threat-intelligence, web-server

## Member repositories
- mitre-attack/attack-navigator (main) score 88

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:52.804730+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:30:29.260542+00:00, confidence not recorded.
  - readme: https://github.com/mitre-attack/attack-navigator (fetched 2026-08-28T04:06:52.804730+00:00, sha bcbb0d87574c)
  - homepage: https://mitre-attack.github.io/attack-navigator (fetched 2026-08-29T10:11:47.741446+00:00, sha 9871e75bc343)
- Data as of 2026-08-30T08:39:29.467469+00:00.
