Find content with the MITRE ATT&CK-Driven Content Recommendation dashboard

Use MITRE ATT&CK to filter for the Splunk content related to MITRE ATT&CK techniques that are associated with many different threat groups.

Steps

  1. In Splunk Security Essentials, navigate to Analytics Advisor > MITRE ATT&CK-Driven Content Recommendation.
  2. In the Categories filter, click the issue category you're concerned with.
  3. (Optional) Adjust the filters for data availability and popularity.

A list of content recommendations appears based on your filters.