SPLK-5002 · Question #62
Engineers are commonly asked to turn data sources like EDR alerts into risk events. Doing so requires a dynamic mapping of the signatures in the rule to MITRE ATT&CK®. Which of the following fields…
The correct answer is D. annotations.mitre_attack.mitre_technique_id. Risk-based alerting expects MITRE ATT&CK® mappings to be provided through the annotations namespace. The correct dynamic field for specifying the ATT&CK technique ID is annotations.mitre_attack.mitre_technique_id, which Splunk uses when generating risk events.
Question
Engineers are commonly asked to turn data sources like EDR alerts into risk events. Doing so requires a dynamic mapping of the signatures in the rule to MITRE ATT&CK®. Which of the following fields could be used to dynamically set the MITRE ATT&CK® technique ID for the EDR alerts?
Options
- Amitre_attack.tactic_id
- Bannotations.mitre_attack.tactic_id
- Cmitre_attack.mitre_technique_id
- Dannotations.mitre_attack.mitre_technique_id
How the community answered
(36 responses)- A3% (1)
- B8% (3)
- C6% (2)
- D83% (30)
Explanation
Risk-based alerting expects MITRE ATT&CK® mappings to be provided through the annotations namespace. The correct dynamic field for specifying the ATT&CK technique ID is annotations.mitre_attack.mitre_technique_id, which Splunk uses when generating risk events.
Topics
Community Discussion
No community discussion yet for this question.