Attacks should have ID's to support mapping items to detection rules
BatteryCandy opened this issue · comments
Ben Pruce commented
Maybe like something like AT0000
so as to not clash with Tactics TA0000
or Techniques T0000
from the original Mitre Matrix?
jukelennings commented
Thanks, @BatteryCandy. Yeah, that's a fair point. We were constantly adding/changing techniques during initial development so I think this type of thing was overlooked. Now we have a stable base of techniques to iterate from, it makes sense to do this though.