CVE-TTP KG links software vulnerabilities to attacker tactics and techniques
arXiv·medium signal
CVE and NVD provide rich technical vulnerability detail but rarely link to attacker behaviors, limiting threat interpretation and response. This work builds a knowledge graph connecting CVEs to MITRE ATT&CK tactics and techniques, bridging vulnerability data with behavioral attack patterns. Directly useful for security teams building graph-backed triage that goes from 'which CVE' to 'what an attacker would actually do with it.'