# Multiple threat frameworks in a single rule

**URL:** <https://discuss.elastic.co/t/multiple-threat-frameworks-in-a-single-rule/377533>\
**Category:** Beats\
**Tags:** beats-module, detection-rules\
**Created:** [April 25, 2025, 6:42pm UTC](https://discuss.elastic.co/t/multiple-threat-frameworks-in-a-single-rule/377533 "2025-04-25T18:42:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nahuel978](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nahuel978](https://discuss.elastic.co/u/nahuel978)\
**Post date:** [April 25, 2025, 6:42pm UTC](https://discuss.elastic.co/t/multiple-threat-frameworks-in-a-single-rule/377533/1 "2025-04-25T18:42:58Z")

</div>

I'm interested in knowing if any Elastic detection rules use two different threat frameworks within the same rule.

According to the ECS documentation:

> **[Threat fields | Elastic Documentation](https://www.elastic.co/docs/reference/ecs/ecs-threat#field-threat-framework)**
>
> Fields to classify events and alerts according to a threat taxonomy such as the MITRE ATT&CK® framework. These fields are for users to classify alerts...

The threat.framework field is defined as a keyword, which suggests it only accepts a single value.

Is it possible for a rule to match more than one framework? How do I address this?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 25, 2025, 10:21pm UTC](https://discuss.elastic.co/t/multiple-threat-frameworks-in-a-single-rule/377533/2 "2025-04-25T22:21:08Z")

</div>

> [@nahuel978](#):
>
> The threat.framework field is defined as a keyword, which suggests it only accepts a single value.

That's not correct, the field is mapped as `keyword`, but every field can have multiple values on it as there is no dedicated array type in Elasticsearch [[documentation](https://www.elastic.co/docs/reference/elasticsearch/mapping-reference/array)]

So you could have something like `threat.framework: ["framework1", "framework2"]`

And you could have a rule that would match any value like this:

```auto
threat.framework: ("framework1" or "framework2")

```

---

<div class="post-metadata">

**Author:** ![nahuel978](https://avatars.discourse-cdn.com/v4/letter/n/5fc32e/32.png) [@nahuel978](https://discuss.elastic.co/u/nahuel978)\
**Post date:** [April 28, 2025, 1:31am UTC](https://discuss.elastic.co/t/multiple-threat-frameworks-in-a-single-rule/377533/3 "2025-04-28T01:31:52Z")

</div>

Hi @leandrojmp! Thank you very much for your response! I understand that even though it's a keyword type, it can even be an array, but its elements must be keywords. Could you give me an example rule that displays this behavior in the framework?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 28, 2025, 2:55am UTC](https://discuss.elastic.co/t/multiple-threat-frameworks-in-a-single-rule/377533/4 "2025-04-28T02:55:41Z")

</div>

> [@nahuel978](#):
>
> Could you give me an example rule that displays this behavior in the framework?

Not sure exactly what kind of example you want and what behavior are you mentioning.

Elastic native integrations uses MITRE only, but the user is free to create rule based on other frameworks.
