Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Manage Matrices

Manage the matrices that are imported from the MITRE TAXII collections. Matrices are a collection of tactics and techniques. You can view the matrices to review if your collections are available in the MITRE-ATT&CK repository.

Before you begin

Role required: sn_sec_tisc.analyst

Procedure

  1. After you enable the MITRE ATT&CK related feed data sources which are available in the base system, click Execute Now to run the integrations and fetch the MITRE related information.

    For more information on enabling the integrations

  2. To view the MITRE ATT&CK Repository data, navigate to Workspaces > Threat Intelligence Security Center > Threat Intel Library > MITRE ATT&CK.

    The MITRE ATT&CK related records are displayed. By default all the records are in enabled state.

    Note: You can enable only those matrices that are relevant to your organization.

  3. Select any Matrix record and click Disable if you want to disable any specific record.

  4. Alternatively, you can create new matrices record by clicking New to manually to create the MITRE ATT&CK matrices.

  5. Fill in the fields appropriately.

    FieldDescription
    NameEnter the name of the matrix.
    SourceSpecifies the threat source from which this record is created.
    ActiveSelect this check box to active the matrix record.
    Created Time In SourceSpecifies the time the object is created in the source.
    Modified Time In SourceSpecifies the time the object is modified in the source.
    DescriptionA description that provides more details and context about the intrusion set, potentially including its purpose and its key characteristics.
    Insights
    NotesAny additional information related to the mitigation.
    Additional Information
    Additional ContextAdd any additional context for this object type.
    CommentsAdd any comments that you might have in addition.

Parent Topic:MITRE-ATT&CK Repository