Skip to content

Add MITRE ATT&CK subtechniques #867

@rw-access

Description

@rw-access

Summary
MITRE is adding subtechniques to ATT&CK soon. It's in beta and soon will be in the major release. We should have integrations and update threat.* to add room for subtechniques.

Example of a subtechnique
https://attack.mitre.org/beta/techniques/T1548/003

Motivation:
Include any context around the suggestion and motivation for opening an issue.

Detailed Design:

Provide additional details around the design of the proposed changes.

  • Field names: threat.subtechnique.{id, name, ref}
  • Example values for the fields 003
  • Suggested appropriate datatypes: same as the other threat fields
  • Any example events that map to the proposed use case(s)
    No events yet, but here's a link
    https://attack.mitre.org/techniques/T1548/003/

Metadata

Metadata

Assignees

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions