Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define the data source and detection tool mapping

Define the data source and detection tool mapping for MITRE-ATT&CK tactics and techniques. The data source mapping provides you with insight into the relevance and availability of the data sources and the detection tools for monitoring the data sources in your environment.

Before you begin

Role required:

  • sn_ti.admin, sn_si.admin: write, delete access
  • sn_ti.read: read access

About this task

You can identify the data sources and the detection tools that your organization needs to detect the techniques effectively.

For example, if your organization focuses on 5 techniques, you may need 10 data sources and 10 detection tools to monitor those sources. Let's say that you identify that your organization does not have two data sources and five detection tools. This exercise gives you visibility into the data sources, their relevance to your organization, and to identify gaps in the coverage. You can also focus on enhancing your environment with the right data sources and detection tools.

All the active tactics, techniques, ID, and data sources are automatically populated based on your TAXII profile

Procedure

  1. Navigate to All > Threat Intelligence > MITRE ATT&CK Administration > Data Source Mapping.

    The following illustration shows the list of tactics, techniques, and their IDs that have been populated based on your collection updates.

Image omitted: mitre-data-source-mapping.png
Map data sources.
FieldDescription
TacticAdversary’s objective or the reason for performing an action.
IDTechnique’s unique identity.
TechniqueHow an adversary achieves a tactical objective by performing an action.
Data SourceData source that is associated with the technique.
Data Source RevokedData source is revoked if set to true, however the data source mapping is still retained.If the data source value is not found in MITRE, then the Data Source Revoked value is automatically marked as true. The data source mapping for a record is revoked if the technique and data source relationships are missing from the updated MITRE data. Default: false
Data Source AvailableAvailability of the data source.
Detection ToolTool that supplements the data source by detecting the techniques that are used. The detection tool is mapped with the alert sensor in SIR.
RevokedThe data source mapping for a record is revoked if the technique and data source relationships are missing from the updated MITRE data.Default: false
  1. Review the listed data sources and modify the value in the Data Source Available field based on your environment.

  2. Note: You cannot edit this entry from the list view.

    In the Detection Tool field, do the following steps:

    1. Click the information icon, and click Open Record.
    2. Unlock Detection Tool entry.
    3. Use the lookup list to select a detection tool. You can multi-select detection tools.
    4. Click Update. In the following illustration, multiple detection tools are added to monitor the data source.
Image omitted: mitre-select-detection-tool.gif
How to map the detection tool.

Parent Topic:MITRE-ATT&CK administration

Related topics

Get started with MITRE-ATT&CK framework

Understand the MITRE to STIX data model

Domain separation and MITRE-ATT&CK

Set up the MITRE-ATT&CK framework

Manage matrices

Manage techniques

Manage mitigations

Manage groups

Manage malware

Manage tools

Manage MITRE relationships

Manage CVE and technique mapping

Extend the MITRE-ATT&CK data

Define the data source and data component mapping

Define the technique detection coverage

Map your technique detection coverage to a technique

Define the mitigation coverage

Map your mitigation coverage to a technique

Create and map detection rules

Auto-extract technique rules for importing MITRE-ATT&CK information

Review threat group and MITRE-ATT&CK techniques mapping

Threat group to technique heatmap definition

Review the MITRE-ATT&CK system properties