Kaspersky Unified Monitoring and Analysis Platform
Mapping MITRE ATT&CK techniques to correlation rules

To map MITRE ATT&CK techniques to correlation rules:

  1. In the KUMA web interface, go to the Resources → Correlation rules section.
  2. Click the name of the correlation rule to open the correlation rule editing window.

    This opens the correlation rule editing window.

  3. On the General tab, clicking the MITRE techniques field opens a list of available techniques. For the convenience of searching, a filter is provided, in which you can enter the name of a technique or the ID of a technique or tactic. One or more MITRE ATT&CK techniques are available for linking to a correlation rule.
  4. Click Save.

The MITRE ATT&CK techniques are mapped to the correlation rule. In the web interface, in the Resources → Correlation rules section, the MITRE techniques column of the edited rule displays the ID of the selected technique, and when you hover over the item, the full name of the technique is displayed, including the ID of the technique and tactic.