MITRE ATT&CK v2
Use the MITRE ATT&CK® feed to fetch MITRE’s Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) content. MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedMitreAttackv2
Configuration parameters
- feed — Fetch indicators
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- feedTags — Tags
- create_relationships — Create relationships
- switch_intrusion_set_to_threat_actor — Save intrusion sets as threat actor indicator types
- feedBypassExclusionList — Bypass exclusion list
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
Commands (4)
- attack-pattern — Looks up the reputation of the indicator in the Enterprise collection only.
- mitre-get-indicator-name — Gets the Attack Pattern value from the Attack Pattern ID in the Enterprise collection only.
- mitre-get-indicators — Retrieves a limited number of indicators.
- mitre-show-feeds — Shows the feed names and IDs from TAXII.