Threat group to technique heatmap definition
Define the threat group to technique heatmap definition so that on the heatmap you can measure and detect the attack patterns that threat groups are using to attack your organization. The probability of an attack using a particular technique increases when you have a high number of attackers.
Before you begin
Role required:
- sn_ti.admin, sn_si.admin: write access
- sn_ti.read: read access
Procedure
Navigate to All > Threat Intelligence > MITRE ATT&CK Administration > Threat Group-Technique Heat Map Definition.
Review the threat group to technique heatmap definition and customize the entries for your environment.
| Field | Description |
|---|---|
| Number of Threat Groups \(min range\) | The minimum number of threat groups using a particular technique. |
| Number of Threat Groups \(max range\) | The maximum number of threat groups using a particular technique. The probability of an attack using a particular technique increases when you have a high number of attackers. |
| Heat Map Color | Color that is assigned to the threat group category. The color that you define is used to highlight the threat group category in the heat map.You can customize the colors using HEX codes and RGB\(A\) values. |
| Text Color | Color that is assigned to the threat group text. The color that you define is used to highlight the threat groups in the heat map.You can customize the colors using HEX codes and RGB\(A\) values. |
| Description | Description about the threat group range and definition. |
**Note:** Ensure that you do not overlap the threat group count ranges if you customize the threat group range \(min or max\).
The following illustration shows the threat group to technique heat map definitions list.
The following illustration shows the threat group to technique heat map definitions list.
- To add an entry, click New, complete the entries, and click Submit.
Parent Topic:MITRE-ATT&CK administration
Related topics
Get started with MITRE-ATT&CK framework
Understand the MITRE to STIX data model
Domain separation and MITRE-ATT&CK
Set up the MITRE-ATT&CK framework
Manage CVE and technique mapping
Define the data source and detection tool mapping
Define the data source and data component mapping
Define the technique detection coverage
Map your technique detection coverage to a technique
Define the mitigation coverage
Map your mitigation coverage to a technique
Create and map detection rules
Auto-extract technique rules for importing MITRE-ATT&CK information