SECURITY CONTROL VALIDATION
AI Threat Builder
AI Threat Builder automates the creation of executable threat scenarios from emerging threats, malware, or campaigns. It researches threats, maps adversary techniques to the MITRE ATT&CK framework, and generates endpoint scenarios that can be saved to a Threat Library.
Let’s see AI Threat Builder in action.
AI Threat Builder automates the creation of executable threat scenarios from emerging threats, malware, or campaigns. It researches threats, maps adversary techniques to the MITRE ATT&CK framework, and generates endpoint scenarios that can be saved to a Threat Library.
The tool can be launched from the main interface, the Threat Builder page, or from an empty search result. Users search the Threat Library by threat name, CVE, SHA, or tag to check if a scenario already exists. If no matching threat is found, a new scenario can be created by entering the threat, malware, or campaign name.
After submission, the system presents identified threat information, attack surface details, source basis, and estimated build time for review and confirmation. Once approved, generation begins and progresses through stages including intelligence gathering, technique mapping, and executable action creation.
The completed scenario includes research findings, an adversary emulation plan, and a generated endpoint scenario. MITRE ATT&CK techniques are mapped with implementation details. The endpoint scenario contains executable actions organized by attacker objective and attack phase, covering stages such as Credential Access, Discovery, Collection, and Command and Control.
Completed threats can be saved to the Threat Library for use in future simulations and campaigns. All AI-generated threats can be filtered and viewed using tags, specifically the AI Generated tag available in the More Filters menu.
Frequently Asked Questions about Picus Planner
TBD