Overview

This page provides an overview of the guidelines for contributing MITRE ATT&CK data into the ThreatConnect Platform. This information is primarily applicable to those developing a Threat Intelligence Feed integration.

Tagging In-Platform Data

For Developer Partners, MITRE ATT&CK data should be contributed in the form of Tags within the ThreatConnect Platform. These Tags can be applied to individual Indicators or Groups based on what seems most appropriate for the data set.

Tag Format

Full MITRE ATT&CK tags should have the following format:

<mitre_attack_technique_id>[.<mitre_attack_subtechnique_id>] - <mitre_attack_technique> - <tactic_abbr> - <data_abbr> - ATT&CK

The fields above have the following definitions:

Partial Data

In the event that only partial data is available, the following rules should be applied:

Example Tags

The following tags are examples of this data model in action: