Define an attack pattern
Define an attack pattern to help threat analysts categorize the attacks.
시작하기 전에
Role required: sn_sec_tisc.analyst
프로시저
다음에 수행할 작업
You can now click any of the following related lists to view additional information about objects associated with the attack pattern.
| Field | Description |
|---|---|
| External References | Lists external references which refer to non-STIX information. This property is used to provide one or more external object identifiers. |
| Campaigns | Lists campaigns associated with this object. |
| Identities | List of identities associated with this object. |
| Indicators | Lists related Indicators of Compromise (IoC) that have been identified by the threat source associated with this object. |
| Intrusion Set | Lists a set of adversarial behaviors and resources with common properties associated with this object. |
| Locations | Lists locations that provide geographic context to this object. |
| Malware | Lists malicious code associated with this object. |
| Threat Actors | Lists individuals, groups, or organizations who act with malicious intent associated with this object. |
| Tools | Lists legitimate software that is used by threat actors to perform attacks associated with this object. |
| Vulnerabilities | Lists a weakness or defect in a software or hardware that attackers exploit which is associated with this object. |
주:
- You can link and unlink the related records associated with this object. For more information, see Link Threat Intel Related Records.
- The various SDOs within the TI library also contains the potential relationships. To establish a relationships between any two objects, you use the Potential Relationships link from the Threat Intel Library to confirm the relationships between the objects. For more information, see Confirm object-object potential relationships.
- Also, use the Related Records section from the objects form view to confirm the relationships between two Objects using the Potential Relationships section available on the form view. For more information on see, Confirm Potential Relationships from Related Records.
- You can add objects to cases. For more information, see Add to Case.