Investigation Canvas MITRE Filters
MITRE filters enables you to create and save filters for Tactics, Techniques, and Procedures (TTPs) associated with specific adversaries and other MITRE technique attributes.
Before you begin
Role required: sn_sec_tisc.analyst
About this task
Analysts can use the filters available on the MITRE card to filter specific actor TTPs that are relevant to adversaries involved in the investigation.
Procedure
Filtering by MITRE Group
Select a MITRE group as APT32 (G1001, see the following screenshot). When you apply this filter, the MITRE matrix updates to display only those techniques that are directly linked to the selected group.
This focused view helps analysts to concentrate specifically on the Tactics, Techniques, and Procedures (TTPs) associated with the selected threat group.
When you apply the filter, a few techniques in the matrix are displayed in blue text, while other techniques appear in gray.
- Blue text: Techniques or sub-techniques shown in blue text indicate those that match the filter criteria.
- Blue text in bold with blue border: Techniques or sub-techniques displayed in bold blue text with a blue border indicate those that match the filter criteria and are associated with one or more nodes on the canvas.
- Gray card: Parent techniques are displayed in gray when they do not directly match the filter criteria (which means they are not linked to the selected group) but are shown to represent the parental relationship to linked sub-techniques that match the filter criteria.