Get started with MITRE-ATT&CK framework
Review the following information before you start setting up your MITRE-ATT&CK framework.
| Setup task | Description |
|---|---|
| Verify that you have assigned the required ServiceNow AI Platform, Threat Intelligence, and Security Incident Response roles. | The following roles are used across the MITRE-ATT&CK features:- The administrator \(admin\) installs the applications from the ServiceNow Store and assigns the security incident administrator \(sn\_si.admin\) and threat intelligence administrator \(sn\_ti.admin\) roles. - sn\_ti.admin - sn\_si.admin - sn\_si.analyst - sn\_ti.read - sn\_ti.write - sn\_ti.mitre\_analyst - The MITRE analyst role has been introduced to allow cross-navigation for the MITRE features between Security Incident Response and Threat Intelligence Support Common. With this role, you can view both the Threat Intelligence MITRE module and the Security Incident Response module in read-only mode. - sn\_si.read For more information, see Setup Threat Intelligence. |
| Verify that the ServiceNow core applications that are required to support the MITRE-ATT&CK module are installed and activated. | Verify that the following Security Operations applications are installed and activated from the ServiceNow Store. If not installed, install and activate one application at a time in the following order to ensure a smooth installation. - Threat Intelligence Support Common UI Components \(sn\_ti\_seismic\) - Version 1.0 or higher - Threat Intelligence Support Common - Version 12.0 or higher - Threat Intelligence - Version 12.0 or higher - Security Incident Response - Version 12.0 or higher For more information on setting up your ServiceNow AI Platform instance for the integration, see get entitlement for a Security Operations product or application and activate a ServiceNow Store application. |
| Domain separation | Verify the domain separation section if you intend to separate data, processes, and administrative tasks. |
Parent Topic:MITRE-ATT&CK administration
Related topics
Understand the MITRE to STIX data model
Domain separation and MITRE-ATT&CK
Set up the MITRE-ATT&CK framework
Manage CVE and technique mapping
Define the data source and detection tool mapping
Define the data source and data component mapping
Define the technique detection coverage
Map your technique detection coverage to a technique
Define the mitigation coverage
Map your mitigation coverage to a technique
Create and map detection rules
Auto-extract technique rules for importing MITRE-ATT&CK information
Review threat group and MITRE-ATT&CK techniques mapping