Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Threat group to technique heatmap definition

Define the threat group to technique heatmap definition so that on the heatmap you can measure and detect the attack patterns that threat groups are using to attack your organization. The probability of an attack using a particular technique increases when you have a high number of attackers.

Before you begin

Role required:

  • sn_ti.admin, sn_si.admin: write access
  • sn_ti.read: read access

Procedure

  1. Navigate to All > Threat Intelligence > MITRE ATT&CK Administration > Threat Group-Technique Heat Map Definition.

  2. Review the threat group to technique heatmap definition and customize the entries for your environment.

FieldDescription
Number of Threat Groups \(min range\)The minimum number of threat groups using a particular technique.
Number of Threat Groups \(max range\)The maximum number of threat groups using a particular technique. The probability of an attack using a particular technique increases when you have a high number of attackers.
Heat Map ColorColor that is assigned to the threat group category. The color that you define is used to highlight the threat group category in the heat map.You can customize the colors using HEX codes and RGB\(A\) values.
Text ColorColor that is assigned to the threat group text. The color that you define is used to highlight the threat groups in the heat map.You can customize the colors using HEX codes and RGB\(A\) values.
DescriptionDescription about the threat group range and definition.
**Note:** Ensure that you do not overlap the threat group count ranges if you customize the threat group range \(min or max\).

The following illustration shows the threat group to technique heat map definitions list.
Image omitted: mitre-threat-group-definition.png
The following illustration shows the threat group to technique heat map definitions list.
  1. To add an entry, click New, complete the entries, and click Submit.

Parent Topic:MITRE-ATT&CK administration

Related topics

Get started with MITRE-ATT&CK framework

Understand the MITRE to STIX data model

Domain separation and MITRE-ATT&CK

Set up the MITRE-ATT&CK framework

Manage matrices

Manage techniques

Manage mitigations

Manage groups

Manage malware

Manage tools

Manage MITRE relationships

Manage CVE and technique mapping

Extend the MITRE-ATT&CK data

Define the data source and detection tool mapping

Define the data source and data component mapping

Define the technique detection coverage

Map your technique detection coverage to a technique

Define the mitigation coverage

Map your mitigation coverage to a technique

Create and map detection rules

Auto-extract technique rules for importing MITRE-ATT&CK information

Review threat group and MITRE-ATT&CK techniques mapping

Review the MITRE-ATT&CK system properties