Skip to content

[Security Solution][Detection Rules]Update schema to match app Mitre ATT&CK validation #87546

@dplumlee

Description

@dplumlee

With the update of the app's Mitre ATT&CK validation in #85481, the detection engine schema wasn't updated with the expectation there would be more overhauled changes to the Mitre fields coming in 7.12. Those have since been reprioritized to a later release so we need to update the Mitre schema, specifically the technique field, to be optional and update the corresponding and affected pre-built rules to match.

Metadata

Metadata

Assignees

Labels

Feature:Detection RulesSecurity Solution rules and Detection EngineQA:ValidatedIssue has been validated by QATeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detections and RespSecurity Detection Response TeambugFixes for quality problems that affect the customer experiencev7.12.0

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions