The report displays the cyber adversary behavior table. The table provide details about the order of the ATT&CK content for a submitted sample. You can capture the report as a screenshot or export it as a json file.
The report provides the following information:
File name – The sample file name.
File hash – The MD5 hash value of the sample.
Severity – The threat level of the sample.
Tactics, Techniques, and Sub-Techniques – The number of tactics, techniques, and the corresponding sub-techniques used by the submitted sample.
ATT&CK Matrix – The matrix shows all tactics (in the first row), and the techniques in the rest of the table. These techniques are further expanded to list all the sub-techniques which are triggered by the sample.
The techniques and sub-techniques are highlighted in various colors to represent the risk level posed by the sample. High risk techniques and sub-techniques are shown in a darker shade of red, while low risk is shown in green. The toggle switch allows you to switch view between showing only the risk items and all items in the table. You can also click each technique or sub-technique to see an overview about the item.
These options are available for the user to interact with the MITRE Matrix report:
Option | Description |
|---|---|
![]() | Toggles the theme of the MITRE Matrix report. These are the themes: Light and Dark. |
![]() | Captures the screenshot of the MITRE Matrix report. |
![]() | Exports the matrix information to Navigator with all the techniques and sub-techniques detected by Intelligent Sandbox. |
![]() | Scrolls the report from right to left. |
![]() | Scrolls the report from left to right. |
![]() | Expands the sub-techniques of all the techniques. |
![]() | Collapse the sub-techniques. |
![]() | Allows you to filter the tactics column to be displayed. |
![]() | Enables and disables the display of technique and sub-technique IDs. |
![]() |
|
Important
Intelligent Sandbox allows you to generate a report for a sample that triggers the behavior linked to MITRE techniques in the sandbox. You cannot generate an ATT&CK report on Intelligent Sandbox if the sample was detected only through any of the following:
GTI URL reputation
Family classification engine
Intelligent Sandbox Machine Learning Prediction
Other static engine
For more information about Matrix, see https://attack.mitre.org/wiki/ATT&CK_Matrix.









