If you want to assess the coverage of the MITRE ATT&CK matrix by your correlation rules:
As a result, you can visually assess the coverage of the MITRE ATT&CK matrix.
Importing the list of MITRE techniques
Only a user with the General Administrator role can import the list of MITRE techniques.
To import the list of MITRE ATT&CK techniques:
KUMA 3.2 supports only the MITRE ATT&CK technique list version 14.1.
This opens the file selection window.
This closes the file selection window.
The list of MITRE ATT&CK techniques is imported into KUMA. You can see the list of imported techniques and the version of the MITRE ATT&CK technique list by clicking View list.
Mapping MITRE techniques to correlation rules
To map MITRE ATT&CK techniques to correlation rules:
This opens the correlation rule editing window.
The MITRE ATT&CK techniques are mapped to the correlation rule. In the web interface, in the Resources → Correlation rules section, the MITRE techniques column of the edited rule displays the ID of the selected technique, and when you hover over the item, the full name of the technique is displayed, including the ID of the technique and tactic.
Exporting correlation rules to MITRE ATT&CK Navigator
To export correlation rules with mapped MITRE techniques to MITRE ATT&CK Navigator:
A file with exported rules is downloaded to your computer.
You can assess the coverage of the MITRE ATT&CK matrix.
Page top