-
Notifications
You must be signed in to change notification settings - Fork 8.6k
[Security Solution][Detection Rules]Update schema to match app Mitre ATT&CK validation #87546
Copy link
Copy link
Closed
Labels
Feature:Detection RulesSecurity Solution rules and Detection EngineSecurity Solution rules and Detection EngineQA:ValidatedIssue has been validated by QAIssue has been validated by QATeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detections and RespSecurity Detection Response TeamSecurity Detection Response TeambugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experiencev7.12.0
Metadata
Metadata
Assignees
Labels
Feature:Detection RulesSecurity Solution rules and Detection EngineSecurity Solution rules and Detection EngineQA:ValidatedIssue has been validated by QAIssue has been validated by QATeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detections and RespSecurity Detection Response TeamSecurity Detection Response TeambugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experiencev7.12.0
Type
Fields
Give feedbackNo fields configured for issues without a type.
With the update of the app's Mitre ATT&CK validation in #85481, the detection engine schema wasn't updated with the expectation there would be more overhauled changes to the Mitre fields coming in 7.12. Those have since been reprioritized to a later release so we need to update the Mitre schema, specifically the
techniquefield, to be optional and update the corresponding and affected pre-built rules to match.