Skip to content

Commit eed605a

Browse files
Adds version table
1 parent ab9d6cb commit eed605a

File tree

1 file changed

+12
-2
lines changed

1 file changed

+12
-2
lines changed

solutions/security/detect-and-alert/mitre-attandckr-coverage.md

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,10 +20,10 @@ Mirroring the MITRE ATT&CK® framework, columns represent major tactics, and cel
2020
To access the **MITRE ATT&CK® coverage** page, find **Detection rules (SIEM)** in the navigation menu or look for “Detection rules (SIEM)” using the [global search field](/explore-analyze/find-and-organize/find-apps-and-objects.md), then go to **MITRE ATT&CK® coverage**.
2121

2222
::::{note}
23-
This page only includes the detection rules you currently have installed, and only rules that are mapped to MITRE ATT&CK®. The coverage page maps detections to the following [MITRE ATT&CK® version](https://attack.mitre.org/resources/updates/updates-april-2025) used by {{elastic-sec}}: `v17.1`. Elastic prebuilt rules that aren’t installed and custom rules that are either unmapped or mapped to a deprecated tactic or technique will not appear on the coverage map.
23+
This page only includes the detection rules you currently have installed, and only rules that are mapped to MITRE ATT&CK®. The coverage page maps detections to [MITRE ATT&CK® versions](https://attack.mitre.org/resources/updates/) used by {{elastic-sec}}.
2424

25-
You can map custom rules to tactics in **Advanced settings** when creating or editing a rule.
2625

26+
Elastic prebuilt rules that aren’t installed and custom rules that are either unmapped or mapped to a deprecated tactic or technique will not appear on the coverage map. You can map custom rules to tactics in **Advanced settings** when creating or editing a rule.
2727
::::
2828

2929

@@ -32,6 +32,16 @@ You can map custom rules to tactics in **Advanced settings** when creating or ed
3232
:screenshot:
3333
:::
3434

35+
Refer to the following table to find the MITRE ATT&CK® version that's mapped to your version of {{elastic-sec}}.
36+
37+
| MITRE ATT\&CK® version | {{elastic-sec}} version |
38+
| :---- | :---- |
39+
| [**v16.1**](https://attack.mitre.org/resources/updates/updates-october-2024/) | **9.0.0, 9.1.0** |
40+
| [**v17.1**](https://attack.mitre.org/resources/updates/updates-april-2025/) | **9.2.0** |
41+
42+
::::{note}
43+
{{serverless-short}} always uses the latest MITRE ATT&CK® versions that's been mapped to {{elastic-sec}}.
44+
::::
3545

3646
## Filter rules [security-rules-coverage-filter-rules]
3747

0 commit comments

Comments
 (0)