Manage groups
Manage the groups that have been imported from the MITRE TAXII collections. Groups are sets of related intrusion activity that are tracked by a common name in the security community. Analysts track clusters of activities using various terms such as threat groups, activity groups, threat actors, intrusion sets, and campaigns. In STIX, groups are known as intrusion sets.
Before you begin
Role required:
- sn_ti.admin: delete access
- sn_ti.read: read access
- sn_ti.write: create, write access
Procedure
Navigate to All > Threat Intelligence > MITRE ATT&CK Repository > Groups.
You can view the listed groups.
Click a group to view all the associated information.
In the following illustration, you can view the details for the Ajax Security Team group, its ID, source, and other related information.
View details for the group and other related information.
To view how these objects are related, click Show Relationships.
Note: To associate the threat groups to a security case for deeper investigation, click Add to Security Case.
What to do next
Use the techniques module to add or modify the groups data.
Parent Topic:MITRE-ATT&CK administration
Related topics
Get started with MITRE-ATT&CK framework
Understand the MITRE to STIX data model
Domain separation and MITRE-ATT&CK
Set up the MITRE-ATT&CK framework
Manage CVE and technique mapping
Define the data source and detection tool mapping
Define the data source and data component mapping
Define the technique detection coverage
Map your technique detection coverage to a technique
Define the mitigation coverage
Map your mitigation coverage to a technique
Create and map detection rules
Auto-extract technique rules for importing MITRE-ATT&CK information
Review threat group and MITRE-ATT&CK techniques mapping