Skip to content

Commit 186f566

Browse files
MITRE ATT&CK® coverage page
1 parent 4eebd7c commit 186f566

File tree

6 files changed

+56
-117
lines changed

6 files changed

+56
-117
lines changed
-84.3 KB
Binary file not shown.

raw-migrated-files/docs-content/serverless/security-rules-coverage.md

Lines changed: 0 additions & 55 deletions
This file was deleted.

raw-migrated-files/docs-content/serverless/security-ui.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -113,6 +113,8 @@ Expand this section to access the following pages:
113113
:class: screenshot
114114
:::
115115

116+
% When we delete this page, we can also delete the serverless--detections-rules-coverage.png file because it's no longer referenced in the Security docs or elsewhere.
117+
116118
* [**MITRE ATT&CK® coverage**](../../../solutions/security/detect-and-alert/mitre-attandckr-coverage.md): Review your coverage of MITRE ATT&CK® tactics and techniques, based on installed rules.
117119

118120
:::{image} ../../../images/serverless--detections-rules-coverage.png

raw-migrated-files/security-docs/security/rules-coverage.md

Lines changed: 0 additions & 55 deletions
This file was deleted.

raw-migrated-files/toc.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -498,7 +498,6 @@ toc:
498498
- file: docs-content/serverless/security-response-actions.md
499499
- file: docs-content/serverless/security-rule-exceptions.md
500500
- file: docs-content/serverless/security-rule-monitoring-dashboard.md
501-
- file: docs-content/serverless/security-rules-coverage.md
502501
- file: docs-content/serverless/security-rules-create.md
503502
- file: docs-content/serverless/security-rules-ui-management.md
504503
- file: docs-content/serverless/security-runtime-fields.md
@@ -885,7 +884,6 @@ toc:
885884
- file: security-docs/security/response-actions-history.md
886885
- file: security-docs/security/response-actions.md
887886
- file: security-docs/security/rule-monitoring-dashboard.md
888-
- file: security-docs/security/rules-coverage.md
889887
- file: security-docs/security/rules-ui-create.md
890888
- file: security-docs/security/rules-ui-management.md
891889
- file: security-docs/security/runtime-fields.md

solutions/security/detect-and-alert/mitre-attandckr-coverage.md

Lines changed: 54 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,60 @@ mapped_urls:
44
- https://www.elastic.co/guide/en/serverless/current/security-rules-coverage.html
55
---
66

7-
# MITRE ATT&CK® coverage
7+
# MITRE ATT&CK® coverage [rules-coverage]
88

9-
% What needs to be done: Lift-and-shift
9+
The **MITRE ATT&CK® coverage** page shows which [MITRE ATT&CK®](https://attack.mitre.org) adversary tactics and techniques are covered by your installed and enabled detection rules. This includes both Elastic prebuilt rules and custom rules.
1010

11-
% Use migrated content from existing pages that map to this page:
11+
Mirroring the MITRE ATT&CK® framework, columns represent major tactics, and cells within each column represent a tactic’s related techniques. Cells are darker when a technique has more rules matching the current filters, as indicated in the **Legend** at the top.
1212

13-
% - [ ] ./raw-migrated-files/security-docs/security/rules-coverage.md
14-
% - [ ] ./raw-migrated-files/docs-content/serverless/security-rules-coverage.md
13+
To access the **MITRE ATT&CK® coverage** page, find **Detection rules (SIEM)** in the navigation menu or look for “Detection rules (SIEM)” using the [global search field](/explore-analyze/find-and-organize/find-apps-and-objects.md), then go to **MITRE ATT&CK® coverage**.
14+
15+
%The following note was included in Serverless docs too, despite it having details that are only relevant for ESS users. Will need to revisit this note at a later time to apply the proper versioning notes or to update.
16+
17+
::::{note}
18+
This page only includes the detection rules you currently have installed, and only rules that are mapped to MITRE ATT&CK®. The coverage page maps detections to the following [MITRE ATT&CK® version](https://attack.mitre.org/resources/updates/updates-april-2024) used by {{elastic-sec}}: `v15.1`. Elastic prebuilt rules that aren’t installed and custom rules that are either unmapped or mapped to a deprecated tactic or technique will not appear on the coverage map.
19+
20+
You can map custom rules to tactics in **Advanced settings** when creating or editing a rule.
21+
22+
::::
23+
24+
25+
:::{image} ../../../images/security-rules-coverage.png
26+
:alt: MITRE ATT&CK® coverage page
27+
:class: screenshot
28+
:::
29+
30+
31+
## Filter rules [_filter_rules]
32+
33+
Use the drop-down filters at the top of the page to control which of your installed detection rules are included in calculating coverage.
34+
35+
* **Installed rule status**: Select to include **Enabled rules**, **Disabled rules**, or both.
36+
* **Installed rule type**: Select to include **Elastic rules** (prebuilt rules), **Custom rules** (user-created rules), or both.
37+
38+
You can also search for a tactic or technique name, technique number, or rule name in the search bar. The search bar acts as a filter for the coverage grid: only rules matching the search term will be included.
39+
40+
::::{note}
41+
Searches for tactics and techniques must match exactly, are case sensitive, and do *not* support wildcards.
42+
::::
43+
44+
45+
46+
## Expand and collapse cells [_expand_and_collapse_cells]
47+
48+
Click **Collapse cells** or **Expand cells** to change how much information the cells display. Cells always include the technique’s name and the number of sub-techniques covered by enabled rules. Expand the cells to also display counts of disabled and enabled rules for each technique.
49+
50+
::::{note}
51+
The counts inside cells are affected by how you filter the page. For example, if you filter the **Installed rule status** to only include **Enabled rules**, then all disabled rule counts will be 0 because disabled rules are filtered out.
52+
::::
53+
54+
55+
56+
## Enable rules [_enable_rules]
57+
58+
You can quickly enable all the rules for a specific technique that you’ve installed, but not enabled. Click the technique’s cell, then click **Enable all disabled** in the popup that appears.
59+
60+
61+
## Learn more about techniques and sub-techniques [_learn_more_about_techniques_and_sub_techniques]
62+
63+
For more information on a specific technique and its sub-techniques, click the technique’s cell, then click the title in the popup that appears. This opens a new browser tab with the technique’s MITRE ATT&CK® documentation.

0 commit comments

Comments
 (0)