MITRE ATT&CK™ Report

Prev Next

The report displays the cyber adversary behavior table. The table provide details about the order of the ATT&CK content for a submitted sample. You can capture the report as a screenshot or export it as a json file.

The report provides the following information:

  • File name – The sample file name.

  • File hash – The MD5 hash value of the sample.

  • Severity – The threat level of the sample.

  • Tactics, Techniques, and Sub-Techniques – The number of tactics, techniques, and the corresponding sub-techniques used by the submitted sample.

  • ATT&CK Matrix – The matrix shows all tactics (in the first row), and the techniques in the rest of the table. These techniques are further expanded to list all the sub-techniques which are triggered by the sample.

The techniques and sub-techniques are highlighted in various colors to represent the risk level posed by the sample. High risk techniques and sub-techniques are shown in a darker shade of red, while low risk is shown in green. The toggle switch allows you to switch view between showing only the risk items and all items in the table. You can also click each technique or sub-technique to see an overview about the item.

These options are available for the user to interact with the MITRE Matrix report:

Option

Description

GUID-06F30E32-C023-402D-930B-8947052E302A-low.png

Toggles the theme of the MITRE Matrix report. These are the themes: Light and Dark.

GUID-5138AAA1-6323-4DB5-A8A0-91A5BC5A629E-low.png

Captures the screenshot of the MITRE Matrix report.

GUID-A317C46A-1F9D-47B9-8C89-ABD3AA76B061-low.png

Exports the matrix information to navigator.json file. You can upload this JSON file here to create a layer on the

Navigator with all the techniques and sub-techniques detected by Intelligent Sandbox.

GUID-CEF76C00-FD3C-4538-9732-8C7E63EC411F-low.png

Scrolls the report from right to left.

GUID-CF4BF441-6935-4954-91A4-5809AC4E8A89-low.png

Scrolls the report from left to right.

GUID-0456D355-5260-45E3-8504-42C7E55DAC63-low.png

Expands the sub-techniques of all the techniques.

GUID-A03580B6-DB35-4F82-806A-2127D2DE4B8A-low.png

Collapse the sub-techniques.

GUID-2F52F0A5-5E39-47A2-B225-B079BC8105A6-low.png

Allows you to filter the tactics column to be displayed.

GUID-E56708ED-C3FB-434D-B1F0-4B75455F8EB7-low.png

Enables and disables the display of technique and sub-technique IDs.

GUID-F19034C0-1B65-4FA1-B6EA-44A2D16E0133-low.png
  • Enable this option to display all the techniques in the matrix table.

  • Disable this option to display only the techniques detected by Intelligent Sandbox.

Important

Intelligent Sandbox allows you to generate a report for a sample that triggers the behavior linked to MITRE techniques in the sandbox. You cannot generate an ATT&CK report on Intelligent Sandbox if the sample was detected only through any of the following:

  • GTI URL reputation

  • Family classification engine

  • Intelligent Sandbox Machine Learning Prediction

  • Other static engine

For more information about Matrix, see https://attack.mitre.org/wiki/ATT&CK_Matrix.