ti_multi_source_ttp_lookup
Enter a MITRE technique ID to correlate threat intel, detection coverage, and ATT&CK data. Get a fused view of associated actors, malware, reports, and telemetry requirements for TTP investigations.
Instructions
ELITE CORRELATION: Given a MITRE technique ID, fan out across MITRE ATT&CK, vendor threat intel blogs, and the local detection index. Returns a fused picture: which actors use it, what malware leverages it, recent vendor reports, detection coverage, and telemetry requirements. The definitive first stop for any TTP investigation.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| technique_id | Yes | MITRE ATT&CK technique ID (e.g., T1059.001) | |
| client_region | No | Optional: client region for relevance context | |
| client_industry | No | Optional: client industry for relevance context |