Search/Tag Rules with MITRE ATT&CK TTP

Hi there,

Not sure if there is currently a way (else, this will be a suggestion) to search rules according to TTPs.

Each rule appears to have at least TTP listed when we click into the rule, but it is not part of the tags at the moment.

My use-case would be to filter for rules associated with a particular TTP (similar to how I am doing it for Sigmac-converted rules). Else, at the moment I would have to guess the relevant keywords to get to these rules, or narrow it down to the technique and then filter from there.

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.