wazuh_search_mitre
Look up MITRE ATT&CK techniques and discover which Wazuh rules detect them for assessing threat coverage.
Instructions
Search the MITRE ATT&CK framework as integrated with Wazuh. Look up techniques, find which Wazuh rules map to a technique, or discover what techniques are covered by your detection ruleset.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| search | No | Search MITRE techniques by name, ID, or keyword (e.g., 'persistence', 'T1547') | |
| technique_id | No | Exact MITRE technique ID (e.g., 'T1547.001') | |
| limit | No | Maximum results (1-200) | |
| offset | No | Pagination offset |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |