Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Review threat group and MITRE-ATT&CK techniques mapping

Review the threat group and techniques object to object relationship mapping information that is imported from the MITRE TAXII collections. This mapping enables you to view the technique group and the corresponding technique mapping.

Before you begin

Role required:

  • sn_ti.admin, sn_si.admin: create, write, delete access
  • sn_ti.read: read access

Procedure

  1. Navigate to All > Threat Intelligence > MITRE ATT&CK Administration > Threat Group-MITRE ATT&CK Techniques.

  2. Right click the Source Object and select Group By Source Object to view all the attack patterns associated with a threat group.

    The following illustration shows the threat group admin@338 and the various attack patterns adopted by this threat group which are part of the enterprise attack source.

Image omitted: mitre-threat-group-technique.gif
Illustration showing the threat group and technique mapping.

Parent Topic:MITRE-ATT&CK administration

Related topics

Get started with MITRE-ATT&CK framework

Understand the MITRE to STIX data model

Domain separation and MITRE-ATT&CK

Set up the MITRE-ATT&CK framework

Manage matrices

Manage techniques

Manage mitigations

Manage groups

Manage malware

Manage tools

Manage MITRE relationships

Manage CVE and technique mapping

Extend the MITRE-ATT&CK data

Define the data source and detection tool mapping

Define the data source and data component mapping

Define the technique detection coverage

Map your technique detection coverage to a technique

Define the mitigation coverage

Map your mitigation coverage to a technique

Create and map detection rules

Auto-extract technique rules for importing MITRE-ATT&CK information

Threat group to technique heatmap definition

Review the MITRE-ATT&CK system properties