Summary
MITRE is adding subtechniques to ATT&CK soon. It's in beta and soon will be in the major release. We should have integrations and update threat.* to add room for subtechniques.
Example of a subtechnique
https://attack.mitre.org/beta/techniques/T1548/003
Motivation:
Include any context around the suggestion and motivation for opening an issue.
Detailed Design:
Provide additional details around the design of the proposed changes.
- Field names:
threat.subtechnique.{id, name, ref}
- Example values for the fields
003
- Suggested appropriate datatypes: same as the other threat fields
- Any example events that map to the proposed use case(s)
No events yet, but here's a link
https://attack.mitre.org/techniques/T1548/003/
Summary
MITRE is adding subtechniques to ATT&CK soon. It's in beta and soon will be in the major release. We should have integrations and update
threat.*to add room for subtechniques.Example of a subtechnique
https://attack.mitre.org/beta/techniques/T1548/003
Motivation:
Include any context around the suggestion and motivation for opening an issue.
Detailed Design:
Provide additional details around the design of the proposed changes.
threat.subtechnique.{id, name, ref}003No events yet, but here's a link
https://attack.mitre.org/techniques/T1548/003/