---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Rollup MITRE-ATT\&CK information from detection rules

# Rollup MITRE-ATT\&CK information from detection rules {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Enable rollup of MITRE-ATT\&CK information from the detection rules to the
security incidents for better security incident and threat analysis.

## Before you begin

Role required: none.  
Ensure that you have performed the following:

* Enable the Rollup MITRE ATT\&ACK information automatically from alert rules to security incidents property in the Properties module. By default, this option is disabled. For more information, see [Review the
  MITRE-ATT\&CK system properties](https://www.servicenow.com/docs/ssnQTt~FrjjemkHHqY74zA "Review the MITRE-ATT&CK system property values.").
* Perform mapping of detection rules to MITRE-ATT\&CK TTPs in Detection Rules - MITRE ATT\&CK TTP Mapping module. The detection rule name must match the alert rule name that triggers the security incident. For more information, see [Create and map detection rules](https://www.servicenow.com/docs/GJQNkvR4BsJndl7s_OJonQ "Create detection rules and map them against the tactics and techniques. With this mapping, you can see the coverage for the detection rules in your organization.").
{#rollup-mitre-attack-information-detection-rules__ul_hpr_335_rsb}

## About this task

If you do not intend to use the base system SIEM auto-extraction rules, then enable
the automatic rollup of MITRE-ATT\&CK TTPs based on the detection rule
mapping. You can populate the alert or event rule that triggers the security
incident in the Alert Rule name field. You can also populate the Alert Rule name field by using SIEM integration, email parsing, manual creation,
and so on.

## Procedure

1. Navigate to MITRE ATT\&CK AdministrationProperties.
2. Enable the Rollup MITRE ATT\&ACK information automatically from alert rules to security incidents property, and click Save.  
   By default, this option is disabled.
3. You need to populate the Alert Rule name field of the security incident with the required alert rules.  
   Note:  
   Ensure that you add the exact Alert Rule name. To add multiple rules, you need to add the rules using a comma separator.
4. Right-click the form, and click Save.  
   If the alert rule name value in the security incident matches a record in the Detection rule - MITRE ATT\&CK TTP Mapping module, the corresponding techniques and tactics associated to the alert rule are linked to the security incident automatically.

5. Open the security incident, select the MITRE ATT\&CK Card and validate whether the techniques are rolled up.
6. Enable Show origin of techniques option to view the origin of the techniques.  
   The origin of techniques should be Detection Rule.
**Related concepts**   

* [MITRE-ATT\&CK heat map and navigator](https://www.servicenow.com/docs/BY9GrF5jowMrXEBCQ9bdHw#mitre-att-ck-heatmap-and-navigator "You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.")
* [Using the MITRE-ATT\&CK dashboard](https://www.servicenow.com/docs/9~FEd0y7MfFhHbb~JXU~4Q#mitre-dashboards "The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.")  
**Related tasks**   

* [Associate MITRE-ATT\&CK information with security incidents](https://www.servicenow.com/docs/EX3yEXjRDXdqeTOcZXKJRw#associate-mitre-with-sir "Associate the MITRE-ATT&CK tactics and techniques to the security incident for better security incident and threat analysis.")
* [Associate MITRE-ATT\&CK information with observables](https://www.servicenow.com/docs/PJrSILm1OxeTCGXqsfFDrQ "Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level.")
* [Associate MITRE-ATT\&CK information with security case](https://www.servicenow.com/docs/qO2DJqVcyJa04ks58~ZPfg "Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.")
* [Rollup MITRE-ATT\&CK information using Threat Lookup results](https://www.servicenow.com/docs/for4thtHfsdEjxkC0txeSg "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Rollup MITRE-ATT\&CK information from child security incidents](https://www.servicenow.com/docs/Y3XRDWupvVk6cXdebShlNw "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Perform link analysis and threat hunting using MITRE-ATT\&CK specific filters](https://www.servicenow.com/docs/x0rcs4zeHGrsRiZg6k6w3A "Correlate and perform link analysis of observables, security incidents, and MITRE-ATT&CK related information so that your organization can start hunting for threats.")

*[\>]: and then


