You can use a heat map with advanced filters to perform an analysis by correlating
security incidents with MITRE-ATT&CK information.
View technique IDs
You can view the MITRE-ATT&CK technique IDs with the technique names when you
select the Display technique IDs filter.
View relevant techniques by priority
To filter the techniques based on their relevant priority in the navigator, select Filter by technique relevant priority filter and select the Relevant Priority from the menu. You can
assign multiple priorities for filtering. You can also point to the techniques in the heat map to know the priority of the technique.
The relevant priority information is based on the prioritization you have set in the Techniques relevant priority field.
View technique detection coverage
To view the overall technique detection coverage in the heat map, select the
Display technique detection coverage filter. The heat map
highlights the visual spectrum of the detection coverage including the blind spots where you
do not have any coverage. The base system scoring definition and the colors have been
defined in the technique
detection coverage. The information has been auto-extracted from the overall
technique detection coverage.
For example, areas of the heat map that are marked in red indicate a lack of detection.
Areas that are marked in blue indicate the presence of full detection capabilities. Areas
that are marked in orange, yellow, and light blue reflect partial detection
capabilities.
- The color visualization is based on the technique definition and
color coding that you define.
- The coverage visualization is based on the technique detection coverage
mapping that you define.
- If you modify the base system coverage definition, the Coverage Type icons do not display with the techniques in the heat map.
注: The heat map works as expected when you modify the same fields as the base
system's-defined technique detection coverage and coverage colors.
In this illustration, you see the technique detection coverage for all the techniques and
sub-techniques and the coverage type with their colors and icons.
View technique mitigation coverage
To view the overall technique mitigation coverage in the heat map, select the Display technique mitigation coverage filter. The heat map highlights the visual spectrum of the mitigation coverage including areas that you do not have
any coverage. The mitigation coverage, colors, and percentage ranges have been defined in the Mitigation Coverage Definition. The information is extracted from the Overall Technique Mitigation Coverage.
For example, techniques highlighted in red indicate no mitigation coverage, orange indicates poor mitigate coverage, and blue indicate excellent mitigation coverage.
- The color visualization is based on the technique mitigation definition and color coding that you define.
- The coverage visualization is based on the technique mitigation coverage mapping that you define.
- If you modify the base system mitigation coverage definition, the Mitigation Coverage Type icons do not display with the techniques in the heat map.
注: The heat map works as expected when you modify the same fields as the
base system's-defined technique mitigation coverage and coverage colors.
View detection and mitigation coverage
You can use the technique detection and technique mitigation coverage filters together to gain an insight into the relevance of the technique detection and mitigate coverage for
your organization.
View threat group
To view the threat group to technique information on the heat map, select Display threat group heat map. You can measure the number of threat groups that are using a particular technique. The probability of
an attack using a particular technique increases when you have a high number of attackers. The threat group ranges, and heat map colors have been defined in the Threat Group-Technique Heat Map Definition.
View Security incidents associated with technique
To view the techniques that are frequently exploited in your organization and that have resulted in security incidents, click Display security incident associated with technique. You can view more
information about each of the associated security incidents when you click the link that open in a new window for analysis.
- Priority: Select Security Incident Priority to filter by the
security incident priority.
- Date range: Select the Security Incident Date Range to filter
security issues by the date range.
- False positives: Select Filter false positives security
incident to remove false positive issues. Selecting this filter reduces
the number of security incidents you see in the heat map.
When you use this filter with the Display technique detection
coverage filter, it provides you with an insight into the relevance of the
technique detection coverage for your organization until the selected date.
For example, when you turn on both filters, you can see that under the Defense Evasion
tactic, the Masquerading technique has no coverage. When you look further, the Masquerading
technique is related to the Masquerade Task or Service, which also has a security incident
that is associated with it. This shows that there is a gap in the technique detection
coverage for the Masquerading technique and you may want to revise the overall technique
detection coverage.
View detection rules
To view if you have the detection rules defined for a particular technique, click
Display detection rules. You can also see each associated detection
rule with their definition.
This information is based on the detection rules mapping that you have defined.
View CVEs associated with technique
To view the Common Vulnerabilities and Exposures (CVE) information that is associated with
each of the techniques, click Display CVEs associated with technique.
The CVE to technique information is based on the information available in the CVE - Technique Mapping
module. This provides you insight into known vulnerabilities and lets you know if
adversaries can potentially exploit your organization.
重要: The heat map is enhanced to display only the relevant CVEs that is
associated with the VITs
To view VITs associated with CVEs and techniques, select Display VITs associated
with CVE and techniques. Additionally, to further filter techniques without
VITs, select Hide techniques without VITs. The CVE and VIT
information you view is fetched from the Vulnerability Response product in your
environment. You can view the filtered list of CVEs and VITs in the heat map and navigate to
each CVE or VIT for every technique from the heat map.
注:
- The Display CVEs associated with technique is available only
when the Vulnerability Response product is installed in your environment.
- The VIT and CVE information is calculated based on the scheduled job you set in the
MITRE-ATT&CK properties. The base system schedule job is set for 24
hours.
When you use this filter with the Display security incident associated with
technique filter, you can learn if the known vulnerabilities have caused
security incidents in your organization.
You can view more information about each CVE to analyze if the CVE is relevant to your organization. To do so, view the vulnerability items. If vulnerability items are created, you can view more information about any associated
CI information in the Vulnerability Response module. You can also review the severity and priority to make informed decisions.
Analyze Security Incidents
To analyze security incidents and review the techniques that are used by an adversary for
an attack, click Analyze Security Incidents. You can add multiple
security incidents for analysis by using comma-separated strings.
This filter helps you to analyze a security incident. You can learn why the incident
occurred, what techniques were exploited, if any known threat actors were involved, if the
threat actors used a particular sequence for an attack, and so on. Because you can analyze
multiple security incidents at the same time, you can correlate the information to see if
they are related or if they are an isolated incident. If the security incidents are related
and you observe a pattern, you can review their progress on the kill chain to stop the
attack or to form a defense strategy for your organization.
When you use the Analyze Security Incidents filter with primary
filters, such as an Adversary Group, you can correlate if known
adversaries are involved. For example, when multiple security incidents are being analyzed,
the techniques that are associated with the security incidents are present in the form of a
kill chain. As you overlap the information with the adversary, you will notice an overlap
between the techniques that are associated with the security incident and the techniques
that are associated with the adversary. Only the overlapped technique information is shown
if both filters are enabled.
Using overlay to analyze security incidents and adversary groups
Use the Enable Overlay / Analyze filter to view the adversary behaviour and analyze one or more of the security incidents and correlate the information to see if an attack is an isolated incident or a
coordinated attack by a known adversary.
For example, you can now view the security incidents and the threat adversary kill chain behaviour in the same view. This view provides overlap information which informs you of the attack and the known adversary behaviour. This
enables you to analyze if this is an isolated attack or a coordinated attack by a known adversary.
Enabling the overlay analyze filter ignores all the primary filters except the Adversary group filter, and ignores the advanced filter Filter by technique relevant priority while
generating a view.
Once you enable the overlay analyze filter, use the color palette to assign colors for the following:
- Analyze Security Incident
- Adversary Group
- Overlay
The following illustration shows that the adversary group APT18 is spread across multiple techniques and tactics in the kill chain. The analysis also shows that there are three techniques which overlay the adversary group and
security incidents that you are tracking.