Review the MITRE-ATT&CK system properties
Review the MITRE-ATT&CK system property values.
Before you begin
Role required: sn_ti.admin, sn_si.admin
Procedure
Navigate to All > Threat Intelligence > MITRE ATT&CK Administration > Properties.
On the form, fill in the fields.
| Field | Description |
|---|---|
| Roll up MITRE ATT&CK information automatically from Observables to security incident\[sn\_ti.rollup\_mitre\_att&ck\_technique\_observable\_si\] | Rollup of MITRE-ATT&CK information from observables to the security incident. For more information, see Associate MITRE ATT&CK information with observables. Default value: Yes |
| Roll up MITRE ATT&CK information automatically from Threat Lookup results to security incident\[sn\_ti.rollup\_mitre\_att&ck\_technique\_threat\_lookup\_si\] | Rollup of MITRE-ATT&CK information from threat lookup results to the security incident. For more information, see Threat lookup auto-extraction.Default value: Yes |
| Roll up MITRE ATT&CK information automatically from alert rules to security incidents\[sn\_ti.rollup\_mitre\_att&ck\_technique\_alert\_rule\_si\] | Rollup of MITRE-ATT&CK TTP information automatically from alert rules to security incidents. For more information, see map detection rules.Default value: No |
| Roll up MITRE ATT&CK information automatically from child security incidents to parent security incident\[sn\_ti.rollup\_mitre\_att&ck\_technique\_child\_si\_si\] | Roll up MITRE-ATT&CK information automatically from child security incidents to parent security incident. Default value: Yes |
| Enabling this property allows mapping of Security Incident Fields like category and sub category with Detection Rules in "Detection Rules - MITRE ATT&CK mapping" table\[sn\_ti.enable\_category\_mapping\_with\_alert\_rule\] | Category and sub-category in the Detection Rules - MITRE ATT&CK mapping page. Default value: No |
| Time\(in hours\) to calculate "CVE - VUL Count"\[sn\_ti.time\_to\_calculate\_cve\_vits\_count\] | The scheduled time in hours to calculate the CVE and VUL information.Default value: 24 |
- Click Save.
Parent Topic:MITRE-ATT&CK administration
Related topics
Get started with MITRE-ATT&CK framework
Understand the MITRE to STIX data model
Domain separation and MITRE-ATT&CK
Set up the MITRE-ATT&CK framework
Manage CVE and technique mapping
Define the data source and detection tool mapping
Define the data source and data component mapping
Define the technique detection coverage
Map your technique detection coverage to a technique
Define the mitigation coverage
Map your mitigation coverage to a technique
Create and map detection rules
Auto-extract technique rules for importing MITRE-ATT&CK information