Roll up of MITRE technique associations
Roll up of MITRE technique associations from observables, indicators, objects, and security incidents which are linked or unlinked from a case record.
시작하기 전에
주:
Role required: sn_sec_tisc.analyst- Roll up of MITRE technique associations for security incidents will roll up the MITRE technique associated data from security incidents to the case management in TISC.
- By default this property sn_sec_tisc.auto_rollup_mitre_data is enabled for the MITRE Technique(s), to be rolled up to case(s) from the associated objects or security incidents automatically.
- If you want to perform on demand roll up of MITRE technique associations then navigate to the more actions within the Case form view and select Roll Up MITRE Techniques option. This operation will happen asynchronously and you can verify the Activity Stream section for the updates on the roll up activity.
이 태스크 정보
- Whenever any entity such as an observable or indicator is linked to any case, then all the MITRE technique associations that are present for that entity are automatically rolled up to the case.
- Whenever any entity such as an observable or indicator is unlinked and removed from the case, then all the MITRE technique associations which are rolled up from the case that are present for that entity will be removed automatically and rolled up to the case.