Managing MITRE ATT&CK Profiles

ThreatStream enables you to create multiple MITRE ATT&CK profiles with their own respective security coverage representation. Any user in your organization, except read-only users, can edit, export, or delete MITRE profiles created within the organization.

To access the MITRE ATT&CK Profiles page in ThreatStream:

  1. Navigate to ThreatStream > Manage > MITRE ATT&CK.

  2. On the MITRE profile page you land, click Manage Profiles or MITRE ATT&CK Profiles.

Note: Read Only users cannot access the MITRE ATT&CK Profiles page. All other users can access the page, create profiles and export profiles, and configure security coverage representation of profiles.

When you access the MITRE ATT&CK Profiles page for the first time, you may see the Migrated MITRE profile. The Migrated profile is your organization's MITRE security coverage configured prior to the implementation of the MITRE profiles functionality. You can continue using the Migrated profile or create a new MITRE profile. See Creating a MITRE ATT&CK Profile for details.

Note: If the Migrated profile is not listed on the MITRE ATT&CK Profiles page, the security coverage representation was not configured for your organization. To configure the security coverage representation of your organization's MITRE ATT&CK framework, you must create a MITRE ATT&CK profile. See Creating a MITRE ATT&CK Profile for details.

On the MITRE ATT&CK Profiles list page, you can perform the following actions:

For instructions on exporting MITRE ATT&CK profiles, refer to Exporting MITRE ATT&CK Profiles.

Additionally, if you use AQL dashboards, you can add MITRE profiles to them. See MITRE ATT&CK Heatmap Visualization Type for details.

Creating a MITRE ATT&CK Profile

Every organization can create up to 50 MITRE profiles.

To create a MITRE ATT&CK profile:

  1. Navigate to ThreatStream > Manage > MITRE ATT&CK.

  2. On the security coverage page of any MITRE profile, click Manage Profiles or MITRE ATT&CK Profiles.

  3. On the MITRE ATT&CK Profiles page, click New.

  4. In the dialog box that opens, enter a meaningful name for the profile.

  5. Click Save.

The new MITRE ATT&CK profile is created.

Alternatively, you can create a MITRE profile from the security coverage page of an existing MITRE profile by clicking Create New Profile on the MITRE ATT&CK Profile drop-down list.

After creating the MITRE profile, you can start configuring its representation of the security. Refer to Configuring Security Coverage of MITRE ATT&CK Profiles for details.

Editing a MITRE ATT&CK Profile

Names of MITRE ATT&CK profiles can be edited.

To edit a MITRE ATT&CK profile's name:

  1. Navigate to ThreatStream > Manage > MITRE ATT&CK.

  2. On the security coverage page of any MITRE profile, click Manage Profiles or MITRE ATT&CK Profiles.

  3. Select the profile whose name you want to edit.


  4. Click Edit. The Edit Profile dialog box opens.

  5. Modify the name of the profile.

  6. Click Save.

The name of the profile is modified.

Deleting MITRE ATT&CK Profiles

On the MITRE ATT&CK Profiles page, you can delete a single profile or in bulk.

To delete MITRE ATT&CK profiles:

  1. Navigate to ThreatStream > Manage > MITRE ATT&CK.

  2. On the security coverage page of any MITRE profile, click Manage Profiles or MITRE ATT&CK Profiles.

  3. Select the profiles you want to delete.

  4. Click Delete.

  5. In the dialog box that opens, click Delete.

The selected MITRE ATT&CK profiles are deleted.