UCM provides a variety of filters, allowing you to focus on the set of rules you are interested in (enabled or not, installed or not, if they came part of a particular extension pack installed, when they were created or modified, etc). Selecting under ATT&CK Actions the option Coverage map and report (top right) and applying the filter on the left side you can also select to focus on rules for which mapping was enabled (True) or not (False); for those that have mapping already enabled, you will see below each of the rules shown in the table the option to uncover the representation of mappings. e.g.:
Clicking into the rule also shows the mapping status, e.g.:
and from there (using the pencil icon) you can edit this (add/change/remove), e.g.:
You can add/change mapping to your rules as well to those that came installed.
------------------------------
Dusan VIDOVIC
------------------------------
Original Message:
Sent: Wed May 24, 2023 01:54 AM
From: Jeffrey Francisco
Subject: QRadar rules to MITRE tactics mapping
Thanks Gladys! I am working on the use case management document for a client but I'm quite new to QRadar and have yet to install Use Case manager in our environment but will check it out as suggested.
------------------------------
Jeffrey Francisco
Original Message:
Sent: Tue May 23, 2023 01:37 PM
From: Gladys Koskas
Subject: QRadar rules to MITRE tactics mapping
Hi Jeffrey
You can view the mapping of all the content (installed and not installed on your box) using the Use Case Manager available on the App Exchange
------------------------------
Gladys Koskas
Original Message:
Sent: Tue May 23, 2023 02:55 AM
From: Jeffrey Francisco
Subject: QRadar rules to MITRE tactics mapping
Hi,
Is there a mapping for the out of the box or standard Qradar detection rules to respective MITRE tactics/techniques?
I am not sure if IBM has an article/guide relating to this but would appreciate if someone could share some reference on this.
Thanks,
Jeffrey
------------------------------
Jeffrey Francisco
------------------------------