Define an attack pattern

  • リリースバージョン: Australia
  • 更新日 2026年03月12日
  • 所要時間:4分
  • Define an attack pattern to help categorize attacks.

    始める前に

    Role required: sn_ti.admin

    手順

    1. Navigate to All > Threat Intelligence > IoC Repository > Attack Patterns.
    2. Click New.
    3. Complete the fields in the form as appropriate.
      FieldDescription
      Name Enter a descriptive name for this attack pattern.
      Spec Version The version of the STIX specification used to represent this object.

      The value of this property must be 2.1 for STIX Objects defined according to this specification.

      Source Specifies the threat source from which this record is created.
      Description Enter a description of the attack pattern.
      Aliases Alternative names to identify this attack pattern.
      Source ID Unique identifier for this object in the threat source.
      Created Time in Source Specifies the time the object is created in the source.
      Modified Time in Source Specifies the time the object is modified in the source.
    4. Click Submit.

    次のタスク

    You can now click any of the following related lists to view additional information about objects associated with the attack pattern.
    Related Links and Related Lists Description
    Show Relationships Opens the STIX Visualizer where you can view the relationship of the STIX object.

    Show Relationships appears only when the object has an associated object.

    External References Lists external references which refer to non-STIX information. This property is used to provide one or more external object identifiers.
    Associated Kill Chain Phases Lists kill chain phases associated with this object.
    Campaigns Lists campaigns associated with this object.
    Course of Actions Lists the associated course of actions with this object that are technical or automated responses (applying patches, reconfiguring firewalls) to prevent an attack.
    Identities List of identities associated with this object.
    Indicators Lists related Indicators of Compromise (IoC) that have been identified by the threat source associated with this object.
    Intrusion Set Lists a set of adversarial behaviors and resources with common properties associated with this object.
    Locations Lists locations that provide geographic context to this object.
    Malware Lists malicious code associated with this object.
    Threat Actors Lists individuals, groups, or organizations who act with malicious intent associated with this object.
    Tools Lists legitimate software that is used by threat actors to perform attacks associated with this object.
    Vulnerabilities Lists a weakness or defect in a software or hardware that attackers exploit which is associated with this object.