Review threat group and MITRE-ATT&CK techniques mapping
Review the threat group and techniques object to object relationship mapping information that is imported from the MITRE TAXII collections. This mapping enables you to view the technique group and the corresponding technique mapping.
Before you begin
Role required:
- sn_ti.admin, sn_si.admin: create, write, delete access
- sn_ti.read: read access
Procedure
Navigate to All > Threat Intelligence > MITRE ATT&CK Administration > Threat Group-MITRE ATT&CK Techniques.
Right click the Source Object and select Group By Source Object to view all the attack patterns associated with a threat group.
The following illustration shows the threat group admin@338 and the various attack patterns adopted by this threat group which are part of the enterprise attack source.
Illustration showing the threat group and technique mapping.
Parent Topic:MITRE-ATT&CK administration
Related topics
Get started with MITRE-ATT&CK framework
Understand the MITRE to STIX data model
Domain separation and MITRE-ATT&CK
Set up the MITRE-ATT&CK framework
Manage CVE and technique mapping
Define the data source and detection tool mapping
Define the data source and data component mapping
Define the technique detection coverage
Map your technique detection coverage to a technique
Define the mitigation coverage
Map your mitigation coverage to a technique
Create and map detection rules
Auto-extract technique rules for importing MITRE-ATT&CK information