Associate MITRE-ATT&CK information with security case
Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.
Before you begin
Role required: sn_si.analyst
Procedure
Navigate to All > Threat Intelligence > Case Management > All Cases.
Select the security case that you want to enrich with the MITRE-ATT&CK information.
From the related list, click Associate MITRE ATT&CK Technique.
In the following illustration, you can see how to navigate from the related list to Associate MITRE ATT&CK Technique, review the source, and add a tactic and technique.
In the source lists, review the Source.
Review the Tactic and Techniques, and add or remove them based on the relevance with the case.
Click Save.
The tactics and techniques that you have added appear in the MITRE-ATT&CK Card.
This illustration shows how to associate MITRE information with a security case.
Parent Topic:Using MITRE-ATT&CK to detect and analyze threats
Parent Topic:Create cases in Security Case Management
Related topics
Associate MITRE-ATT&CK information with security incidents
Associate MITRE-ATT&CK information with observables
Rollup MITRE-ATT&CK information using Threat Lookup results
Rollup MITRE-ATT&CK information from detection rules
Rollup MITRE-ATT&CK information from child security incidents
Perform link analysis and threat hunting using MITRE-ATT&CK specific filters
MITRE-ATT&CK heat map and navigator