Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Rollup MITRE-ATT&CK information from detection rules

Enable rollup of MITRE-ATT&CK information from the detection rules to the security incidents for better security incident and threat analysis.

Before you begin

Role required: none.

Ensure that you have performed the following:

  • Enable the Rollup MITRE ATT&ACK information automatically from alert rules to security incidents property in the Properties module. By default, this option is disabled. For more information, see Review the MITRE-ATT&CK system properties.
  • Perform mapping of detection rules to MITRE-ATT&CK TTPs in Detection Rules - MITRE ATT&CK TTP Mapping module. The detection rule name must match the alert rule name that triggers the security incident. For more information, see Create and map detection rules.

About this task

If you do not intend to use the base system SIEM auto-extraction rules, then enable the automatic rollup of MITRE-ATT&CK TTPs based on the detection rule mapping. You can populate the alert or event rule that triggers the security incident in the Alert Rule name field. You can also populate the Alert Rule name field by using SIEM integration, email parsing, manual creation, and so on.

Procedure

  1. Navigate to MITRE ATT&CK Administration > Properties.

  2. Enable the Rollup MITRE ATT&ACK information automatically from alert rules to security incidents property, and click Save.

    By default, this option is disabled.

  3. You need to populate the Alert Rule name field of the security incident with the required alert rules.

    Note: Ensure that you add the exact Alert Rule name. To add multiple rules, you need to add the rules using a comma separator.

  4. Right-click the form, and click Save.

    If the alert rule name value in the security incident matches a record in the Detection rule - MITRE ATT&CK TTP Mapping module, the corresponding techniques and tactics associated to the alert rule are linked to the security incident automatically.

Image omitted: mitre-rollup-detection-rule.gif
This illustration shows how to roll up MITRE information from the detection rules to a security incident.
  1. Open the security incident, select the MITRE ATT&CK Card and validate whether the techniques are rolled up.

  2. Enable Show origin of techniques option to view the origin of the techniques.

    The origin of techniques should be Detection Rule.

Parent Topic:Using MITRE-ATT&CK to detect and analyze threats

Related topics

Associate MITRE-ATT&CK information with security incidents

Associate MITRE-ATT&CK information with observables

Associate MITRE-ATT&CK information with security case

Rollup MITRE-ATT&CK information using Threat Lookup results

Rollup MITRE-ATT&CK information from child security incidents

Perform link analysis and threat hunting using MITRE-ATT&CK specific filters

MITRE-ATT&CK heat map and navigator

Using the MITRE-ATT&CK dashboard