If you have not enabled automatic rollup of MITRE-ATT&CK information, you
can do this manually.
Before you begin
Role required: sn_si.analyst
About this task
If you have enabled automatic roll up of MITRE-ATT&CK information from Threat Lookup results to security
incident, then the information is automatically rolled up. If you have not enabled
automatic rollup, you can do this manually.
Procedure
-
Navigate to .
-
Select the security incident that you want to enrich with the MITRE-ATT&CK information.
-
Click Show All Related Lists and the Threat
Lookup Results tab.
-
Select the observable and then from the Actions menu, click Roll up
MITRE ATT&CK Information to SI.
You can select multiple observables and rollup the information.
-
Click Reload to confirm the changes.
The following illustration shows how to select an observable and roll up the
Threat Lookup results to the security incident.
You can view the MITRE-ATT&CK Card to confirm that the
Threat Lookup results have been rolledup to the security incident.