Supporting Add on for MITRE

Splunk Community

Supporting Add on for MITRE

Supporting Add on for MITRE
This app provides a method to ingest MITRE ATT&CK® tactics, techniques, and subtechniques into Splunk events. The app contains a mitre_techniques KVStore with the metadata provided from ATT&CK to help enrich alerts and ES Correlations without needing to navigate back to the MITRE ATT&CK website. IMPORTANT: Standalone Search Head (will not work on Search Head Cluster) Direct internet connection required (no proxy)
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.