Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Extend the MITRE-ATT&CK data

Extend the MITRE-ATT&CK repository data in the ServiceNow AI Platform by enriching it.

Before you begin

Role required:

  • sn_ti.admin: delete access
  • sn_ti.read: read access
  • sn_ti.write: create, write access

About this task

You can extend the Malware, Group, Mitigation, and Tool objects to a technique in the MITRE-ATT&CK repository.

You can create a new object and establish a relationship between a technique and the new object in the MITRE ATT&CK Repository module, but you can't define the relationship type in this module. For more information about defining relationship types, see object to object relationships. To define a relationship type, navigate to the Threat Intelligence > IoC Repository > Object-Object Relationships module.

If you map the relationship type between an existing technique and an existing object, then you must define the technique as the target object and the object as the source object. To do so, navigate to the IoC Repository > Object-Object Relationships module.

You can create a group and associate it with an attack pattern, but in the MITRE ATT&CK Repository, you can only establish the relationship between the group and the attack pattern. To define the object-to-object relationship type, you must do so in the IoC Repository.

Note: Any customizations that you make to the objects are saved during scheduled updates.

Procedure

  1. Navigate to Threat Intelligence > MITRE ATT&CK Repository > Techniques.

  2. Click a techniques or sub-technique to view all the associated information with this technique.

    In the following illustration, you can see that the Botnet (T1584.005) technique is not associated with any group. If you have additional information about a technique or sub-technique, you can enrich it by adding or modifying the information.

Image omitted: mitre-botnet.png
Associate a Botnet with another object.
  1. Click a related list to enrich its data to associate it with a new group.

    In the following illustration, a group, Custom1, has been associated with the Botnet sub-technique.

Image omitted: mitre-extend-object.gif
Extend MITRE object information by enriching its data.

Parent Topic:MITRE-ATT&CK administration

Related topics

Get started with MITRE-ATT&CK framework

Understand the MITRE to STIX data model

Domain separation and MITRE-ATT&CK

Set up the MITRE-ATT&CK framework

Manage matrices

Manage techniques

Manage mitigations

Manage groups

Manage malware

Manage tools

Manage MITRE relationships

Manage CVE and technique mapping

Define the data source and detection tool mapping

Define the data source and data component mapping

Define the technique detection coverage

Map your technique detection coverage to a technique

Define the mitigation coverage

Map your mitigation coverage to a technique

Create and map detection rules

Auto-extract technique rules for importing MITRE-ATT&CK information

Review threat group and MITRE-ATT&CK techniques mapping

Threat group to technique heatmap definition

Review the MITRE-ATT&CK system properties