MITRE ATT&CK

Created by Lakshmi Vasanth, Modified on Wed, 21 Aug, 2024 at 11:13 AM by Lakshmi Vasanth

The MITRE ATT&CK section displays data regarding the tactics used in cyber attacks to identify potential threats.  This data is organized in the Dashboard and Intelligence tabs.


Dashboard

The Dashboard displays the MITRE ATT&CK-related data in charts for easy understanding.  The available charts are as follows:


  • Alerts Evolution Over Time

The Alerts Evolution Over Time chart tracks the number of security alerts over a specific period, categorized by different attack types.


Upon hovering over the chart, the statistical data of a specific attack-type security alert over time is displayed.



  • Top Tactics

The Top Tactics is a pie chart displaying the percentage distribution of different attack tactics.

Upon hovering over the chart, the statistical percentage data of a specific attack tactic is displayed.



  • MITRE Attacks By Tactic

The MITRE Attacks By Tactic chart displays a bar chart, showing the count of various MITRE ATT&CK tactics.


Upon hovering over the chart, the statistical data of a specific MITRE ATT&CK tactic is displayed.


  • Rule Level By Attack 

The Rule Level By Attack displays a bar chart showing the rule level triggered by specific attacks.


Upon hovering over the chart, the statistical data for a specific rule level triggered by a particular attack is displayed.



  • Rule Level By Tactic

The Rule Level By Tactic is a bar chart showing the rule levels triggered by different attack tactics.


Upon hovering over the chart, the statistical data for a specific rule level triggered by a particular attack tactic is displayed.



Intelligence

The Intelligence tab displays data in tabular format, showing different groups associated with the MITRE ATT&CK and their details.  The data is organized in various tabs such as the following:


  • Groups

The Groups tab displays all the MITRE ATT&CK groups, providing details such as ID, name, and descriptions for each group.



  • Mitigation

The Mitigation tab displays all the MITRE ATT&CK groups, providing details such as ID, name, descriptions for each group, and the associated mitigation strategies for the selected device.



  • Software

The Software tab displays details of MITRE ATT&CK software with the associated ID for the entry, name of the software, and description that provides a link to more detailed information.



  • Tactics

The Tactics tab displays MITRE ATT&CK tactics and the associated details like the ID of the tactic in the MITRE ATT&CK framework, the Name of the tactic, and the Description of the tactic involved with what the adversary is trying to achieve. 



  • Techniques

The Techniques tab displays a list of specific techniques attackers use with their details such as the ID, Name, and Description of the attack pattern.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article