Get a first look at what's coming. The Developer Passport Australia Release Preview kicks off March 12. Dive in! 

How to extract unused MITRE TTPS and show on dashboard

vsiva
Tera Contributor

We are extracting  MITRE TTPS from SPLUNK ES  from notable events or correlation searches and mapped in Splunk profiles. And showing in Security incident response form under MITRE ATTCK card related tabs using BR.

Now we want to show the difference of used and unused MITRE TTPS like

Show techniques not yet triggered or mapped.

Unused TTPs = All MITRE TTPs - Used TTPs
 
These unused TTPS should be displayed on ServiceNow MITRE dashboard.

 

0 REPLIES 0