Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

Mapping Custom Rules or Building Blocks to MITRE Tactics

 

Create your own rule and building block mappings or modify IBM QRadar default mappings to map your custom rules and building blocks to specific tactics and techniques.

Create your own rule and building block mappings or modify IBM QRadar default mappings to map your custom rules and building blocks to specific tactics and techniques.

  1. In the report section of the Rules Explorer page, select the relevant rule. Tip

    Filter on the rule name, tactic, or technique to find the rule you want to edit or search by using a regular expression. You can also use the Group filter to select the group you want to search, such as authentication or compliance.

  2. On the Investigate rules page, click the pencil icon in the MITRE ATT&CK section.
  3. On the MITRE ATT&CK Mapping page, customize rule-mapping options by either adding new tactics or editing existing ones.Tip

    The MITRE ATT&CK Mapping page shows only the mappings that are directly related to a rule. You can see mappings that the rule inherited from its dependencies in the rule details section of the Investigate rules page or in the Rules Explorer report. Use the Mapping source column in the report, or in the MIITRE ATT&CK section of the rule details page, to see the relationships between the rules and their mappings. Or, if you create content extensions for the IBM Security App Exchange, and you want to map rules in them, export the mappings and upload them when you submit your content.

    1. To add or remove tactics with the rule or building block, click the plus sign icon, select the relevant tactics, and then click Apply.

    2. To add or remove techniques for a tactic, click the plus sign icon for the tactic, select the relevant techniques, and then click Apply.

    3. To include the tactic and technique in the heat map calculation, keep the Enable checkbox selected.

    4. Select the confidence level for each tactic and click Save. You must set a confidence level; otherwise, you can't save the mapping.

    5. To reset to the IBM default mappings, click the Reset icon in the Tactics or Techniques columns.

  4. After you finish customizing your mappings, click Save or Save and close to return to the Rules Explorer page.

To edit multiple rules or building blocks at one time, see Editing MITRE Mappings in Multiple Rules or Building Blocks.