Manage CVE and technique mapping
Manage the CVE and technique information that is mapped after you import the MITRE TAXII collections.
Before you begin
Role required:
- sn_ti.admin: delete access
- sn_si.admin: create, write, delete access
- sn_ti.read: read access
- sn_ti.write: create, write access
Note: The CVE-Technique Mapping module is available only when the Vulnerability Response product is installed in your environment.
About this task
Once you import the MITRE TAXII collections you can view the CVEs in your environment and their relationship with the associated MITRE-ATT&CK techniques. You can also create associations with CVEs and the attack patterns.
Procedure
Navigate to All > Threat Intelligence > MITRE ATT&CK Repository > CVE - Technique Mapping.
You can view the listed CVEs and techniques.
Click a CVE to view the vulnerability database entry.
In the following illustration, you can view the details for the CVE list and for the vulnerability database entry for CVE-2014-7169.
The illustration shows the CVE list and the vulnerability database entry.
To add an entry, click New, map the CVE to an Attack Pattern, and click Submit.
In the following illustration, a new entry is created by mapping CVE-2014-0515 with the Masquerading attack pattern.
The illustration shows how to create a new entry and map a CVE to a technique.
Parent Topic:MITRE-ATT&CK administration
Related topics
Get started with MITRE-ATT&CK framework
Understand the MITRE to STIX data model
Domain separation and MITRE-ATT&CK
Set up the MITRE-ATT&CK framework
Define the data source and detection tool mapping
Define the data source and data component mapping
Define the technique detection coverage
Map your technique detection coverage to a technique
Define the mitigation coverage
Map your mitigation coverage to a technique
Create and map detection rules
Auto-extract technique rules for importing MITRE-ATT&CK information
Review threat group and MITRE-ATT&CK techniques mapping