Viewing Attack Flow Details
The Attack Flow Details page provides a visual display of the relationships between attack patterns, objects and elements that belong to an attack flow. Additionally, you can view details of every attack pattern, objects and elements.
Below is the example of the MITRE attack flow v1.0.
Description and details of the MITRE attack flow v1.0. The details include the date when the attack flow was created, date when the attack flow was modified, source, names of actors and their aliases.
Initial MITRE attack pattern.
An artifact that is being attacked, compromised or exploited.
Attack pattern details. You can view a summary of details of an attack pattern by clicking on an attack pattern icon in an attack flow visual. An attack pattern may contain property details, required MITRE permissions, MITRE tactics, an attack pattern description, and a link to the associated attack pattern in ThreatStream. Click View Details to go to the attack pattern details page. For more information, see Viewing Attack Pattern Details.
Below is the example of the MITRE attack flow v2.0.
Description and details of the MITRE attack flow v2. The details include the date when the attack flow was created, date when it was modified, source, names of actors and their aliases.
Initial MITRE attack pattern.
Attack condition associated with the attack pattern.
An attack flow may include the following elements: actions, assets, conditions, OR operators, and AND operators.
Infrastructure—the STIX object associated with the attack pattern.
An attack flow may include the following STIX objects: attack patterns, tools, intrusion sets, course of actions, infrastructures, notes, groupings, opinions, reports, identities, campaigns, locations, indicators, malware, malware analysis, threat actors, vulnerabilities, and observed data. Additionally, an attack flow may also include such elements as domain name, URL, email address, user account, email message, file, directory, artifact, Windows registry key, mutex, IPV4 address, IPV6 address, network traffic, autonomous system, Mac address, X509 certificate, process, and software.
Attack pattern details. You can view a summary of details of an attack patterns by clicking on an attack pattern icon in an attack flow visual. An attack pattern may include the following summary details: confidence score, description, technique ID, and MITRE ID. Click View Details to go to the attack pattern details page. For more information, see Viewing Attack Pattern Details.