CoolFace
Datasetpublic

relayshieldadmin/mitre-attack-groups

RelayShield MITRE ATT&CK Group-Technique Mapping A structured slice of MITRE ATT&CK Enterprise data: 189 named threat actor groups, each mapped to its associated ATT&CK techniques and software, with descriptions and source citations. This is a cleaned, machine-readable export of MITRE's public STIX bundle — useful if you want group→technique mappings without parsing STIX yourself. Fields Field Type Description group_id string MITRE ATT&CK group ID (e.g.… See the full description on the dataset page: https://huggingface.co/datasets/relayshieldadmin/mitre-attack-groups.

sourceHugging Faceotherupdated 2mo agoView on Hugging Face
0likes29downloads
Dataset Card

RelayShield MITRE ATT&CK Group-Technique Mapping

A structured slice of MITRE ATT&CK Enterprise data: 189 named threat actor groups, each mapped to its associated ATT&CK techniques and software, with descriptions and source citations.

This is a cleaned, machine-readable export of MITRE's public STIX bundle — useful if you want group→technique mappings without parsing STIX yourself.

Fields

FieldTypeDescription
group_idstringMITRE ATT&CK group ID (e.g. G0056)
namestringPrimary group name
aliaseslist[string]Known aliases for the same group
country_originstringAttributed country of origin, when publicly known ("Unknown" otherwise)
descriptionstringMITRE's public group description, including citation markers
urlstringCanonical attack.mitre.org group page
technique_idslist[string]ATT&CK technique IDs (e.g. T1036.004) associated with this group
software_idslist[string]ATT&CK software IDs associated with this group
technique_countintConvenience count of technique_ids

Coverage

  • 189 named MITRE ATT&CK groups, each mapped to its techniques and software (~24 techniques per group on average)
  • Sourced from MITRE ATT&CK's public Enterprise STIX bundle
  • Distinct from RelayShield's separate malware-family taxonomy (sourced from Malpedia + MITRE Software, not part of this dataset) — this file covers threat groups and their techniques only, not malware families

Source & maintenance

This slice is generated from the same weekly MITRE ATT&CK ingestion pipeline that feeds RelayShield's live threat-intelligence API — a commercial API/MCP server that cross-references this group/technique taxonomy against a proprietary corpus (40+ monitored criminal-marketplace channels, 3M+ IOCs, infostealer logs, breach data) that isn't part of this public dataset. This file is the public taxonomy layer only.

Try the live tools this dataset backs: RelayShield Agentic Attack Surface (MCP server) · api.relayshield.net/developers (PAYG API, x402-enabled)

License / attribution

This dataset is derived from the MITRE ATT&CK® framework, made available by MITRE under its Terms of Use. ATT&CK® is a registered trademark of The MITRE Corporation. This dataset is not affiliated with or endorsed by MITRE.

If you use this dataset, please cite both MITRE ATT&CK and this derived export:

MITRE ATT&CK. https://attack.mitre.org
RelayShield MITRE ATT&CK Group-Technique Mapping. https://huggingface.co/datasets/relayshieldadmin/mitre-attack-groups