Correlate and perform link analysis of observables, security incidents, and MITRE-ATT&CK related information so that your organization can start hunting for
threats.
始める前に
Role required: sn_ti.mitre_analyst, sn_si.read
このタスクについて
After you associate the security incidents with MITRE-ATT&CK information, you can use the MITRE-ATT&CK specific
filters for threat hunting. Use the MITRE-ATT&CK filters with the existing
Security Incident Response filters to correlate and perform link
analysis.
手順
-
Navigate to .
-
Click Update Personalized List to add the MITRE columns.
-
Select a filter condition so that you can view MITRE related
information and associations with security incidents or observables:
- MITRE-ATT&CK Adversary Group
- MITRE-ATT&CK Data Source
- MITRE-ATT&CK Procedure (Malware)
- MITRE-ATT&CK Procedure (Tools)
- MITRE-ATT&CK Tactic
- MITRE-ATT&CK Technique
-
Create a filter condition that is based on the above criteria and click
Run to perform a link analysis or correlation between
security incidents, observables, and MITRE-ATT&CK related
information.
注: The MITRE-ATT&CK data is stored as a string and you can only
use contains as the operator for filter
conditions.
For example, if you want to review that a configuration
item (CI) is compromised, you select a CI. You then correlate the CI with
techniques that are present by adding a MITRE-ATT&CK Technique
ID. You can then continue to build your filter criteria to correlate the
information and for threat hunting.