MITRE ATT&CK® Sub Technique
The MITRE ATT&CK® Sub Technique object describes the sub technique ID and/or name associated to an attack, as defined by ATT&CK® Matrix.
Attributes
Caption | Name | Type | Description |
---|---|---|---|
Name | name |
String |
The name of the attack sub technique, as defined by ATT&CK® Matrix. For example: Scanning IP Blocks .
|
Raw Data | raw_data |
JSON | The event data as received from the event source. |
Record ID | record_id |
String | Unique identifier for the object |
Source URL | src_url |
URL String |
The versioned permalink of the attack sub technique, as defined by ATT&CK® Matrix. For example: https://attack.mitre.org/versions/v14/techniques/T1595/001/ .
|
Unique ID | uid |
String |
The unique identifier of the attack sub technique, as defined by ATT&CK® Matrix. For example: T1595.001 .
|
Unmapped Data | unmapped |
Unmapped[] | The attributes that are not mapped to the event schema. The names and values of those attributes are specific to the event source. |
Relationships
Inbound Relationships
These objects and events reference MITRE ATT&CK® Sub Technique in their attributes:
Outbound Relationships
MITRE ATT&CK® Sub Technique references the following objects and events in its attributes:
This page describes qdm-1.3.2+ocsf-1.3.0
Updated 2 months ago