
Completed
Posted
Absolutely — here’s a full, detailed breakdown of the MITRE ATT&CK Excel-based assessment tool you're requesting, including: All customer requirements so far Best practices to enhance it for real-world use Clear deliverables for a freelancer Official MITRE sources and design considerations --- MITRE ATT&CK Excel Assessment – Full Requirements and Breakdown --- Objective Create a professional, interactive, and automated Excel-based assessment tool that allows SHI or customers to map and assess their security capabilities against the MITRE ATT&CK® Enterprise framework. This tool should allow both self-guided and SHI-led virtual assessments. --- 1. MITRE ATT&CK Framework Foundation Reference Framework: MITRE ATT&CK Enterprise Matrix Total Tactics: 14 Total Techniques: ~193 techniques (not including sub-techniques) Each technique should have: Technique ID (e.g., T1566) Technique Name Direct link to MITRE page At least one assessment question Associated tactic(s) for grouping Tactics in Order: 1. Reconnaissance (TA0043) 2. Resource Development (TA0042) 3. Initial Access (TA0001) 4. Execution (TA0002) 5. Persistence (TA0003) 6. Privilege Escalation (TA0004) 7. Defense Evasion (TA0005) 8. Credential Access (TA0006) 9. Discovery (TA0007) 10. Lateral Movement (TA0008) 11. Collection (TA0009) 12. Command and Control (TA0011) 13. Exfiltration (TA0010) 14. Impact (TA0040) > Each tactic tab in Excel should include every associated technique from the MITRE matrix. --- 2. Excel Workbook Structure Tabs Required One tab per tactic (14 total) Summary Dashboard tab Reference tab (optional) – lists all techniques with metadata --- 3. Columns Per Tactic Sheet Each sheet should have these columns: 1. Technique ID 2. Technique Name 3. MITRE Link 4. Assessment Question 5. Current State (Dropdown) 6. Tools in Use (Dropdown with free entry option) 7. Owner (Dropdown with free entry option) 8. Risk Level (Dropdown) 9. Comments 10. Score (Auto-calculated) --- 4. Dropdown Options (For Freelancer to Implement) Current State (Scored Automatically) Not Started → 0 In Progress → 1 Completed → 2 N/A → excluded from scoring Tools in Use CrowdStrike SentinelOne Defender for Endpoint Splunk Sysmon Darktrace Palo Alto Cortex Rapid7 Proofpoint Mimecast Other (Allow multiple selection via VBA) Owner SOC IT IAM Team AppSec GRC Endpoint Team Cloud Team Other (Allow multiple selection via VBA) Risk Level High Medium Low --- 5. Features & Automation Automated Scoring Add scoring logic for each technique row using IF() formulas or VBA: Full = 2, Partial = 1, None = 0, N/A = BLANK Show coverage % per tactic tab Formula: =SUM(Score Column)/((# of Techniques - N/As) * 2) Conditional Formatting Red fill for “Not Started” Yellow fill for “In Progress” Green fill for “Completed” Apply to Current State and Score columns for quick visual identification Multi-Select Dropdowns Use VBA to enable multiple selections in: Current State (if you want optional tagging like “Completed, Validated”) Tools in Use Owner (VBA example already provided above) --- 6. Summary Dashboard Requirements This tab should pull data from each tactic tab and display: Summary Calculations Auto-calculate total coverage % per tactic Count of techniques by status Risk Priority Logic: High if <50% coverage Medium if 50–79% Low if ≥80% --- 7. Additional Enhancements (Optional but Recommended) Reference Tab Include a tab with: All techniques Their associated tactic Link to MITRE Source: [login to view URL] Filtering Enable filtering by: Risk Level Owner Tool Current State Printable Report Option to export dashboard to PDF for executive summary Navigator Export Eventually enable export to MITRE ATT&CK Navigator via JSON for visualization (advanced, optional) --- 8. Supporting MITRE Resources ATT&CK Techniques List: [login to view URL] ATT&CK Tactics: [login to view URL] MITRE Navigator Tool: [login to view URL] --- Freelancer Deliverables The final Excel file should: Be in .xlsm format (macro-enabled) Contain: 14 tactic tabs, with all techniques per MITRE Summary Dashboard with formulas Full scoring automation and conditional formatting VBA-enabled multi-select dropdowns Be clean, well-labeled, and tested for: Formula correctness Dropdown functionality Visual clarity User protection (e.g., locking formula cells)
Project ID: 39234217
25 proposals
Remote project
Active 4 mos ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
25 freelancers are bidding on average $47 USD/hour for this job

$38 USD in 40 days
7.6
7.6

$40 USD in 40 days
7.2
7.2

$25 USD in 30 days
6.5
6.5

$25 USD in 40 days
5.1
5.1

$25 USD in 40 days
4.2
4.2

$25 USD in 211 days
3.5
3.5

$25 USD in 40 days
3.4
3.4

$38 USD in 40 days
2.9
2.9

$25 USD in 38 days
0.0
0.0

$38 USD in 40 days
0.0
0.0

$38 USD in 70 days
0.0
0.0

$28 USD in 40 days
0.0
0.0

$38 USD in 2 days
0.0
0.0

Austin, United States
Payment method verified
Member since Mar 23, 2025
$8-15 USD / hour
$10-30 CAD
₹750-1250 INR / hour
$10-30 USD
₹500 INR
$10-30 USD
₹600-1500 INR
$10-30 USD
₹12500-37500 INR
₹600-1500 INR
₹600-1500 INR
$10-30 USD
₹600-1500 INR
$10-30 USD
₹600-20000 INR
$250-750 USD
$30-250 USD
£20-250 GBP
₹1500-12500 INR
₹600-1500 INR