MITRE ATT&CK® & ATLAS™

attack

The MITRE ATT&CK® & ATLAS™ object describes the tactic, technique, sub-technique & mitigation associated to an attack.

Attributes

CaptionNameTypeDescription
MITRE MitigationmitigationMITRE Mitigation[]

The Mitigation object describes the MITRE ATT&CK® or ATLAS™ Mitigation ID and/or name that is associated to an attack.

Raw Dataraw_dataJSON

Group:context
The event data as received from the event source.

Record IDrecord_idString

Group:primary
Unique identifier for the object

MITRE Sub-techniquesub_techniqueMITRE Sub-technique[]

The Sub-technique object describes the MITRE ATT&CK® or ATLAS™ Sub-technique ID and/or name associated to an attack.

MITRE TactictacticMITRE Tactic[]

The Tactic object describes the MITRE ATT&CK® or ATLAS™ Tactic ID and/or name that is associated to an attack.

TacticstacticsMITRE Tactic[]

The Tactic object describes the tactic ID and/or tactic name that are associated with the attack technique, as defined by ATT&CK® Matrix.

🚧 WARNING: DEPRECATED

Tactics has been deprecated since 1.1.0. Use the tactic attribute instead.

MITRE TechniquetechniqueMITRE Technique[]

The Technique object describes the MITRE ATT&CK® or ATLAS™ Technique ID and/or name associated to an attack.

UnmappedunmappedUnmapped[]

Data from the source that was not mapped into the schema.

VersionversionString

The ATT&CK® or ATLAS™ Matrix version.

Relationships

MITRE ATT&CK® & ATLAS™ shown in context

Inbound Relationships

These objects and events reference MITRE ATT&CK® & ATLAS™ in their attributes:

Outbound Relationships

MITRE ATT&CK® & ATLAS™ references the following objects and events in its attributes:

This page describes qdm-1.5.1+ocsf-1.6.0