MITRE ATT&CK®

attack

The MITRE ATT&CK® object describes the tactic, technique & sub-technique associated to an attack as defined in ATT&CK® Matrix.

Attributes

CaptionNameTypeDescription
Raw Dataraw_dataJSON

Group:context
The event data as received from the event source.

Record IDrecord_idString

Group:primary
Unique identifier for the object

Sub Techniquesub_techniqueMITRE ATT&CK® Sub Technique[]

The Sub Technique object describes the sub technique ID and/or name associated to an attack, as defined by ATT&CK® Matrix.

TactictacticMITRE ATT&CK® Tactic[]

The Tactic object describes the tactic ID and/or name that is associated to an attack, as defined by ATT&CK® Matrix.

TacticstacticsMITRE ATT&CK® Tactic[]

The Tactic object describes the tactic ID and/or tactic name that are associated with the attack technique, as defined by ATT&CK® Matrix.

🚧 WARNING: DEPRECATED

Tactics has been deprecated since 1.1.0. Use the tactic attribute instead.

TechniquetechniqueMITRE ATT&CK® Technique[]

The Technique object describes the technique ID and/or name associated to an attack, as defined by ATT&CK® Matrix.

UnmappedunmappedUnmapped[]

Data from the source that was not mapped into the schema.

VersionversionString

The ATT&CK® Matrix version.

Relationships

MITRE ATT&CK® shown in context

Inbound Relationships

These objects and events reference MITRE ATT&CK® in their attributes:

Outbound Relationships

MITRE ATT&CK® references the following objects and events in its attributes:

This page describes ocsf-1.4.0