# Detection-Rules - Subtechniques

**URL:** <https://discuss.elastic.co/t/detection-rules-subtechniques/269658>\
**Category:** Elastic Security\
**Created:** [April 9, 2021, 4:51am UTC](https://discuss.elastic.co/t/detection-rules-subtechniques/269658 "2021-04-09T04:51:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inf/32/85793_2.png) [@inf](https://discuss.elastic.co/u/inf)\
**Post date:** [April 9, 2021, 4:51am UTC](https://discuss.elastic.co/t/detection-rules-subtechniques/269658/1 "2021-04-09T04:51:19Z")

</div>

As I understand from the [official GitHub repository for detection-rules](https://github.com/elastic/detection-rules), sub-techniques are already used as part of the existing rules. One example can be found [here](https://github.com/elastic/detection-rules/blob/main/rules/azure/initial_access_azure_active_directory_powershell_signin.toml).

However, from what I see in the [latest guide](https://www.elastic.co/guide/en/security/current/rules-api-create.html#threats-object-create), it is still not rolled out yet. There is no sub-technique under the `technique` object (which is otherwise implied by the example seen above).

I was trying to import these rules, and hence found out about this difference - the initial part of an example error message is `{"statusCode":400,"error":"Bad Request","message":"[request body]: invalid keys \"subtechnique,[{\"id\":\"T1078.004\",\"name\":\"Cloud Accounts\",\"reference\":\"https://attack.mitre.org/techniques/T1078/004/\"}],subtechnique,[{\"id\":\"T1550.001\"...`

Questions:

1. Are my observations above correct, or am I missing something out?
2. Is there anyway that I can continue to import these rules in the meantime? (I am presuming that I would otherwise have to wait for 7.13 to be out, which would presumably contain the sub-techniques as part of the existing field, or find an alternative solution in the meantime)

Thank you!

---

<div class="post-metadata">

**Author:** ![inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inf/32/85793_2.png) [@inf](https://discuss.elastic.co/u/inf)\
**Post date:** [April 11, 2021, 2:13am UTC](https://discuss.elastic.co/t/detection-rules-subtechniques/269658/2 "2021-04-11T02:13:08Z")

</div>

Issue resolved by upgrading my Elastic Stack from 7.10 to 7.12.

However, I am still not sure why the latest guide does not have the sub-technique under the `technique` object.

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [April 13, 2021, 1:08am UTC](https://discuss.elastic.co/t/detection-rules-subtechniques/269658/3 "2021-04-13T01:08:09Z")

</div>

Thanks for the update @inf -- glad that resolved the issue! 🙂 As for the docs, I've created [this issue](https://github.com/elastic/security-docs/issues/628) to update them and let the docs folks know so thanks for the heads up here too.

Cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inf/32/85793_2.png) [@inf](https://discuss.elastic.co/u/inf)\
**Post date:** [April 13, 2021, 1:47am UTC](https://discuss.elastic.co/t/detection-rules-subtechniques/269658/4 "2021-04-13T01:47:59Z")

</div>

Thank you for getting back to me on this @spong!

Greatly appreciate it! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2021, 1:48am UTC](https://discuss.elastic.co/t/detection-rules-subtechniques/269658/5 "2021-05-11T01:48:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
