attack_map
Map verified findings to MITRE ATT&CK techniques to frame the kill chain at the end of an investigation.
Instructions
Map the corroborated findings recorded so far to MITRE ATT&CK techniques. The mapping is deterministic and runs only over CONFIRMED and INFERRED findings, so the technique coverage is grounded in verified evidence and each technique cites the findings that evidence it. Use this near the end of an investigation to frame the kill chain.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |