CaseBender home page
English
Search...
⌘K
Getting Started
Introduction
Quickstart Guide
Deployment
Deployment Overview
Deploy to Google Cloud Run
Deploy to AWS
Deploy to Azure
Deploy to DigitalOcean
Alert Management
Alert List View
Alert Detail View
Alert Observables
Alert TTPs
Similar Alerts
AI Insights
Case Management
Case Management
Creating Cases
Case Workflows
Working with Cases
Case Settings
AI Features in Case Management
Task Management
Task Management
Creating Tasks
Task Workflows
Working with Tasks
Task Settings
Task Analytics
Analytics
Analytics
Alert Analytics
Case Analytics
Task Analytics
Analyst Performance
Audits
Audit Logs
Change History
Status Tracking
Activity Logs
Compliance Monitoring
Settings
Introduction
Integrations
Workflows
AI Settings
Custom Fields
Observable Types
Attack Patterns
Alert Statuses
Case Statuses
Templates
Branding
CaseBender home page
English
Search...
⌘K
Support
Get Started
Get Started
Search...
Navigation
Alert Management
Alert TTPs
Documentation
API Reference
Documentation
API Reference
Support
Get Started
On this page
Overview
MITRE ATT&CK Integration
Framework Overview
Mapping Capabilities
Managing TTPs
Adding Techniques
Bulk Operations
TTP Properties
Documentation
Evidence Collection
Procedure Details
Analysis Features
Pattern Recognition
Impact Assessment
Visualization
Matrix View
Timeline View
Best Practices
Next Steps
Alert Management
Alert TTPs
Track tactics, techniques, and procedures associated with alerts
Overview
The TTPs (Tactics, Techniques, and Procedures) tab provides a comprehensive view of the MITRE ATT&CK techniques and tactics associated with an alert, helping analysts understand and document adversary behavior.
MITRE ATT&CK Integration
Framework Overview
Enterprise ATT&CK Matrix
Mobile ATT&CK Matrix
ICS ATT&CK Matrix
Pre-ATT&CK Tactics
Mapping Capabilities
Technique selection
Sub-technique support
Tactic categorization
Confidence scoring
Managing TTPs
Adding Techniques
Browse or search ATT&CK matrix
Select relevant technique
Choose sub-techniques if applicable
Set confidence level
Add supporting evidence
Bulk Operations
Import technique list
Export TTP mapping
Bulk update confidence
Remove multiple techniques
TTP Properties
Technique ID
Technique name
Sub-technique details
Confidence level
Supporting evidence
Detection status
Mitigation status
Documentation
Evidence Collection
Observable links
Screenshot attachments
Log excerpts
Analysis notes
Procedure Details
Implementation specifics
Tool usage
Command syntax
Execution timeline
Analysis Features
Pattern Recognition
Common technique combinations
Campaign correlation
Actor attribution
Similar incidents
Impact Assessment
Technique severity
Asset scope
Business impact
Risk scoring
Visualization
Matrix View
ATT&CK matrix navigation
Technique highlighting
Sub-technique expansion
Coverage mapping
Timeline View
Technique execution order
Time-based correlation
Pattern identification
Campaign tracking
Best Practices
Technique Mapping
Verify technique matches
Document evidence clearly
Set appropriate confidence
Link to observables
Documentation
Detail procedure specifics
Include context
Reference sources
Update findings
Analysis
Look for patterns
Compare with known actors
Assess impact
Plan mitigations
Next Steps
Similar Alerts
Find related alerts
AI Insights
Get AI-powered analysis
Alert Observables
Similar Alerts
Assistant
Responses are generated using AI and may contain mistakes.