MITRE-ATT&CK Integration for Behavioural HARM-based Attack Simulation

Authors

DOI:

https://doi.org/10.34190/eccws.25.1.4911

Keywords:

Automated attack simulation, HARM, HARMer, MITRE ATT&CK, Threat-informed defence, Automated redteaming, Vulnerability modelling, Adversary behaviour

Abstract

Automated attack simulation has emerged as an important approach for assessing the security of complex
networked systems in a scalable and repeatable manner. Frameworks based on the Hierarchical Attack Representation
Model (HARM), such as HARMer, support automated vulnerability discovery, attack-path generation, and attack execution.
However, existing HARM-based approaches remain largely vulnerability-centric, relying on Common Vulnerabilities and
Exposures (CVE) identifiers that provide limited insight into adversary behaviour. Consequently, generated attack paths are
often difficult to interpret from a threat-informed defence perspective. This research investigates the integration of the
MITRE ATT&CK framework into a HARM-based automated attack simulation pipeline to improve the behavioural
interpretability of simulation outputs. An experimental methodology was adopted using an enhanced HARMer framework
deployed within controlled and isolated environments. Vulnerability information obtained through automated scanning was
used to construct HARM models representing network reachability and host-level vulnerabilities. Identified CVEs were
systematically mapped to ATT&CK tactics and techniques using vulnerability descriptions, exploit documentation, and
ATT&CK framework definitions. The resulting behavioural information was incorporated into attack planning and
visualisation processes. To evaluate the effectiveness of the proposed enhancement, four evaluation indicators were
defined: Mapping Coverage Rate (MCR), Behavioural Annotation Rate (BAR), Technique Coverage (TC), and Attack Path
Preservation (APP). These indicators were used to assess the feasibility of behavioural enrichment while ensuring that the
automation and scalability characteristics of the original HARMer framework were maintained. The results demonstrate that
CVE-based vulnerabilities can be systematically enriched with ATT&CK semantics, enabling attack paths to be interpreted as
sequences of adversary behaviours rather than isolated technical exploits. Behaviour-enhanced attack planning preserved
the original path-generation logic while providing additional contextual information regarding attacker tactics and
techniques. Furthermore, ATT&CK-based visualisation provided an intuitive representation of behavioural coverage across
simulated attack scenarios, supporting clearer interpretation of attack activity. The study contributes a practical approach
for integrating behavioural threat intelligence into HARM-based automated attack simulation. By combining vulnerabilitydriven
attack modelling with ATT&CK-based behavioural semantics, the proposed framework advances automated redteaming
beyond purely technical exploit analysis towards more interpretable, threat-informed, and operationally relevant
security assessment.

Downloads

Published

2026-06-15