map_incident
Map incident indicators and behaviors to MITRE ATT&CK techniques for structured assessments and recommended actions.
Instructions
Map incident IOCs/behaviors to ATT&CK techniques
Args: query: Optional query parameter (regulation ref, identifier, or input data). api_key: Optional MEOK API key for Pro+ tier features.
Returns: JSON with structured assessment, regulation refs, and recommended actions.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| query | No | ||
| api_key | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |