Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Understand the MITRE to STIX data model

Review the terminology used by MITRE and STIX to efficiently use and understand the MITRE-ATT&CK™ framework in the ServiceNow AI Platform.

MITRE objects to STIX mapping

STIX is a language for describing cyber threat information in a standardized and structured manner. The parent data model in the Threat Intelligence module are the STIX objects. While the MITRE objects are a subset to the parent STIX data model. In the MITRE-ATT&CK framework, MITRE provides similar STIX information with certain labels and objects.

MITRE terminologySTIX terminology
TechniqueAttack Pattern
MitigationCourse of Action
GroupsIntrusion Sets
MalwareMalware
ToolTool

Extending data in the Threat Intelligence module

You can maintain a list of Threat Intelligence threat sources and import the needed STIX data that includes an extensive set of cyber threat information. You can also use the TAXII profiles to facilitate automated exchange of cyber threat information.

Note: For more information, see define a threat source and create a TAXII profile.

Extending data in the MITRE-ATT&CK module

You can extend the Malware, Group, Mitigation, and Tool objects to a technique in the MITRE-ATT&CK repository.

You can create an object and establish a relationship between a technique and the new object in the MITRE ATT&CK Repository module, but you can't define the relationship type in this module. To define a relationship type, navigate to the Threat Intelligence > IoC Repository > Object-Object Relationships module.

If you map the relationship type between an existing technique and an existing object, then you must define the technique as the target object and the object as the source object. To do so, navigate to the IoC Repository > Object-Object Relationships module.

You can create a group and associate it with an attack pattern, but in the MITRE ATT&CK Repository, you can only establish the relationship between the group and the attack pattern. To define the object-to-object relationship type, you must do so in the IoC Repository.

Note: For more information, see extend MITRE-ATT&CK data and IoC repository.

Parent Topic:MITRE-ATT&CK administration

Related topics

Get started with MITRE-ATT&CK framework

Domain separation and MITRE-ATT&CK

Set up the MITRE-ATT&CK framework

Manage matrices

Manage techniques

Manage mitigations

Manage groups

Manage malware

Manage tools

Manage MITRE relationships

Manage CVE and technique mapping

Extend the MITRE-ATT&CK data

Define the data source and detection tool mapping

Define the data source and data component mapping

Define the technique detection coverage

Map your technique detection coverage to a technique

Define the mitigation coverage

Map your mitigation coverage to a technique

Create and map detection rules

Auto-extract technique rules for importing MITRE-ATT&CK information

Review threat group and MITRE-ATT&CK techniques mapping

Threat group to technique heatmap definition

Review the MITRE-ATT&CK system properties