Using MITRE-ATT&CK to detect and analyze threats
Use the MITRE-ATT&CK framework across the Threat Intelligence and the SIR module to detect and analyze threats to your organization.
- Associate MITRE-ATT&CK information with security incidents
Associate the MITRE-ATT&CK tactics and techniques to the security incident for better security incident and threat analysis. - Associate MITRE-ATT&CK information with observables
Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level. - Associate MITRE-ATT&CK information with security case
Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level. - Rollup MITRE-ATT&CK information using Threat Lookup results
If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually. - Rollup MITRE-ATT&CK information from detection rules
Enable rollup of MITRE-ATT&CK information from the detection rules to the security incidents for better security incident and threat analysis. - Rollup MITRE-ATT&CK information from child security incidents
If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually. - Perform link analysis and threat hunting using MITRE-ATT&CK specific filters
Correlate and perform link analysis of observables, security incidents, and MITRE-ATT&CK related information so that your organization can start hunting for threats. - MITRE-ATT&CK heat map and navigator
You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage. - Using the MITRE-ATT&CK dashboard
The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.
Parent Topic:MITRE-ATT&CK framework overview
Related topics