get_groups_using_technique
Identify threat actor groups associated with specific MITRE ATT&CK techniques by STIX ID to analyze attack patterns and enhance threat intelligence.
Instructions
Get groups using a technique by its STIX ID
Args: technique_stix_id: Technique STIX ID to check what groups are associated with it. domain: Domain name ('enterprise', 'mobile', or 'ics') include_description: Whether to include description in the output (default is False)
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| technique_stix_id | Yes | ||
| domain | No | enterprise | |
| include_description | No |