Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Review the MITRE-ATT&CK system properties

Review the MITRE-ATT&CK system property values.

Before you begin

Role required: sn_ti.admin, sn_si.admin

Procedure

  1. Navigate to All > Threat Intelligence > MITRE ATT&CK Administration > Properties.

  2. On the form, fill in the fields.

FieldDescription
Roll up MITRE ATT&CK information automatically from Observables to security incident\[sn\_ti.rollup\_mitre\_att&ck\_technique\_observable\_si\]Rollup of MITRE-ATT&CK information from observables to the security incident. For more information, see Associate MITRE ATT&CK information with observables. Default value: Yes
Roll up MITRE ATT&CK information automatically from Threat Lookup results to security incident\[sn\_ti.rollup\_mitre\_att&ck\_technique\_threat\_lookup\_si\]Rollup of MITRE-ATT&CK information from threat lookup results to the security incident. For more information, see Threat lookup auto-extraction.Default value: Yes
Roll up MITRE ATT&CK information automatically from alert rules to security incidents\[sn\_ti.rollup\_mitre\_att&ck\_technique\_alert\_rule\_si\]Rollup of MITRE-ATT&CK TTP information automatically from alert rules to security incidents. For more information, see map detection rules.Default value: No
Roll up MITRE ATT&CK information automatically from child security incidents to parent security incident\[sn\_ti.rollup\_mitre\_att&ck\_technique\_child\_si\_si\]Roll up MITRE-ATT&CK information automatically from child security incidents to parent security incident. Default value: Yes
Enabling this property allows mapping of Security Incident Fields like category and sub category with Detection Rules in "Detection Rules - MITRE ATT&CK mapping" table\[sn\_ti.enable\_category\_mapping\_with\_alert\_rule\]Category and sub-category in the Detection Rules - MITRE ATT&CK mapping page. Default value: No
Time\(in hours\) to calculate "CVE - VUL Count"\[sn\_ti.time\_to\_calculate\_cve\_vits\_count\]The scheduled time in hours to calculate the CVE and VUL information.Default value: 24
  1. Click Save.

Parent Topic:MITRE-ATT&CK administration

Related topics

Get started with MITRE-ATT&CK framework

Understand the MITRE to STIX data model

Domain separation and MITRE-ATT&CK

Set up the MITRE-ATT&CK framework

Manage matrices

Manage techniques

Manage mitigations

Manage groups

Manage malware

Manage tools

Manage MITRE relationships

Manage CVE and technique mapping

Extend the MITRE-ATT&CK data

Define the data source and detection tool mapping

Define the data source and data component mapping

Define the technique detection coverage

Map your technique detection coverage to a technique

Define the mitigation coverage

Map your mitigation coverage to a technique

Create and map detection rules

Auto-extract technique rules for importing MITRE-ATT&CK information

Review threat group and MITRE-ATT&CK techniques mapping

Threat group to technique heatmap definition