Rollup MITRE-ATT&CK information using Threat Lookup results
If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.
Before you begin
Role required: sn_si.analyst
About this task
If you have enabled automatic roll up of MITRE-ATT&CK information from Threat Lookup results to security incident, then the information is automatically rolled up. If you have not enabled automatic rollup, you can do this manually.
Procedure
Navigate to All > Security Incidents > Show All Incidents.
Select the security incident that you want to enrich with the MITRE-ATT&CK information.
Click Show All Related Lists and the Threat Lookup Results tab.
Select the observable and then from the Actions menu, click Roll up MITRE ATT&CK Information to SI.
You can select multiple observables and rollup the information.
Click Reload to confirm the changes.
The following illustration shows how to select an observable and roll up the Threat Lookup results to the security incident.
Manually rollup threat lookup results.
You can view the MITRE-ATT&CK Card to confirm that the Threat Lookup results have been rolledup to the security incident.
Parent Topic:Using MITRE-ATT&CK to detect and analyze threats
Related topics
Associate MITRE-ATT&CK information with security incidents
Associate MITRE-ATT&CK information with observables
Associate MITRE-ATT&CK information with security case
Rollup MITRE-ATT&CK information from detection rules
Rollup MITRE-ATT&CK information from child security incidents
Perform link analysis and threat hunting using MITRE-ATT&CK specific filters