Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Associate MITRE-ATT&CK information with security case

Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.

Before you begin

Role required: sn_si.analyst

Procedure

  1. Navigate to All > Threat Intelligence > Case Management > All Cases.

  2. Select the security case that you want to enrich with the MITRE-ATT&CK information.

  3. From the related list, click Associate MITRE ATT&CK Technique.

    In the following illustration, you can see how to navigate from the related list to Associate MITRE ATT&CK Technique, review the source, and add a tactic and technique.

  4. In the source lists, review the Source.

  5. Review the Tactic and Techniques, and add or remove them based on the relevance with the case.

  6. Click Save.

    The tactics and techniques that you have added appear in the MITRE-ATT&CK Card.

Image omitted: mitre-case-management.gif
This illustration shows how to associate MITRE information with a security case.

Parent Topic:Using MITRE-ATT&CK to detect and analyze threats

Parent Topic:Create cases in Security Case Management

Related topics

Associate MITRE-ATT&CK information with security incidents

Associate MITRE-ATT&CK information with observables

Rollup MITRE-ATT&CK information using Threat Lookup results

Rollup MITRE-ATT&CK information from detection rules

Rollup MITRE-ATT&CK information from child security incidents

Perform link analysis and threat hunting using MITRE-ATT&CK specific filters

MITRE-ATT&CK heat map and navigator

Using the MITRE-ATT&CK dashboard

Add artifacts to a case