Skip to content

Commit 849e9d1

Browse files
Updates MITRE docs to currently used version v17.1 (#2518)
🟢 **NOTE TO SELF:** Merge this on Tuesday, Sep 3, 20205 and then open PRs for #2791 ## Summary Updates the 9.x and Serverless docs to show that detection rules will use the MITRE ATT&CK® version v17.1 in 9.2 and next weeks' Serverless release. Because we need to show that earlier versions of 9.x (specifically 9.0.0-9.0.6 and 9.1.0-9.1.3) use an older version of MITRE ATT&CK® (v16.1), I created a table to show how the versions are mapped. ## Related - Doc issue: elastic/kibana#166152 - Dev PR: elastic/kibana#231375 ## Preview https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/2518/solutions/security/detect-and-alert/mitre-attandckr-coverage --------- Co-authored-by: Nastasha Solomon <[email protected]> Co-authored-by: Nastasha Solomon <[email protected]>
1 parent 985794a commit 849e9d1

File tree

1 file changed

+9
-2
lines changed

1 file changed

+9
-2
lines changed

solutions/security/detect-and-alert/mitre-attandckr-coverage.md

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,10 +20,10 @@ Mirroring the MITRE ATT&CK® framework, columns represent major tactics, and cel
2020
To access the **MITRE ATT&CK® coverage** page, find **Detection rules (SIEM)** in the navigation menu or look for “Detection rules (SIEM)” using the [global search field](/explore-analyze/find-and-organize/find-apps-and-objects.md), then go to **MITRE ATT&CK® coverage**.
2121

2222
::::{note}
23-
This page only includes the detection rules you currently have installed, and only rules that are mapped to MITRE ATT&CK®. The coverage page maps detections to the following [MITRE ATT&CK® version](https://attack.mitre.org/resources/updates/updates-april-2024) used by {{elastic-sec}}: `v16.1`. Elastic prebuilt rules that aren’t installed and custom rules that are either unmapped or mapped to a deprecated tactic or technique will not appear on the coverage map.
23+
This page only includes the detection rules you currently have installed, and only rules that are mapped to MITRE ATT&CK®. The coverage page maps detections to [MITRE ATT&CK® versions](https://attack.mitre.org/resources/updates/) used by {{elastic-sec}}.
2424

25-
You can map custom rules to tactics in **Advanced settings** when creating or editing a rule.
2625

26+
Elastic prebuilt rules that aren’t installed and custom rules that are either unmapped or mapped to a deprecated tactic or technique will not appear on the coverage map. You can map custom rules to tactics in **Advanced settings** when creating or editing a rule.
2727
::::
2828

2929

@@ -32,6 +32,13 @@ You can map custom rules to tactics in **Advanced settings** when creating or ed
3232
:screenshot:
3333
:::
3434

35+
Refer to the following table to find the MITRE ATT&CK® version that's mapped to your version of {{elastic-sec}}.
36+
37+
| MITRE ATT\&CK® version | {{elastic-sec}} version |
38+
| :---- | :---- |
39+
| [v16.1](https://attack.mitre.org/resources/updates/updates-october-2024/) | • 9.0.0-9.0.6 <br> • 9.1.0-9.1.3|
40+
| [v17.1](https://attack.mitre.org/resources/updates/updates-april-2025/) | • {applies_to}`stack: ga 9.2.0` <br> • {{serverless-short}} |
41+
3542

3643
## Filter rules [security-rules-coverage-filter-rules]
3744

0 commit comments

Comments
 (0)