---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# MITRE-ATT\&CK heat map and navigator

# MITRE-ATT\&CK heat map and navigator {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 13 minutes to read

You can use the MITRE-ATT\&CK heat map and navigator for basic navigation and
to visualize your overall technique detection coverage.

## Overview of the MITRE-ATT\&CK heat map and navigator {#mitre-att-ck-heatmap-and-navigator__section_ypf_zdc_xnb}

You can use the navigator with the primary filters for basic navigation and observation of
ATT\&CK matrices. The heat map highlights the spectrum of the detection coverage including
the blind spots where your organization does not have any coverage. This is available after you
map the [technique detection
coverage.](https://servicenow-prod.fluidtopics.net/5tLotF08usuUwSe~1xicBw "Map your overall technique detection coverage with the technique that enables your organization to detect specific adversary techniques.")  
With the heat map and navigator, you can:

* Quickly and efficiently identify your organization's detection capabilities and highlight gaps in the technique detection coverage.
* Hunt for threats and perform correlation of threats using associated features.
{#mitre-att-ck-heatmap-and-navigator__ul_dvk_1tl_xnb}
**Related concepts**   

* [Using the MITRE-ATT\&CK dashboard](https://servicenow-prod.fluidtopics.net/imunAQ_IeggrtvWlWddKEw#mitre-dashboards "The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.")  
**Related tasks**   

* [Associate MITRE-ATT\&CK information with security incidents](https://servicenow-prod.fluidtopics.net/J3z4piiw4XfDN0sHmTmUlw#associate-mitre-with-sir "Associate the MITRE-ATT&CK tactics and techniques to the security incident for better security incident and threat analysis.")
* [Associate MITRE-ATT\&CK information with observables](https://servicenow-prod.fluidtopics.net/OFTiAqgRV6uKVG2hbJBVWg "Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level.")
* [Associate MITRE-ATT\&CK information with security case](https://servicenow-prod.fluidtopics.net/vR0MxG6Hmr3ZC~hcuvahbg "Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.")
* [Rollup MITRE-ATT\&CK information using Threat Lookup results](https://servicenow-prod.fluidtopics.net/8dXSmKyPBaSVx3tsFqhZAw "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Rollup MITRE-ATT\&CK information from detection rules](https://servicenow-prod.fluidtopics.net/VlfxcmUxRdd_cpzNcHN1TA "Enable rollup of MITRE-ATT&CK information from the detection rules to the security incidents for better security incident and threat analysis.")
* [Rollup MITRE-ATT\&CK information from child security incidents](https://servicenow-prod.fluidtopics.net/Ojj0100Xlq4DON4dNamzMQ "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Perform link analysis and threat hunting using MITRE-ATT\&CK specific filters](https://servicenow-prod.fluidtopics.net/AGX_TGwRVFohiU0FJYsdlA "Correlate and perform link analysis of observables, security incidents, and MITRE-ATT&CK related information so that your organization can start hunting for threats.")

## Access the MITRE-ATT\&CK heat map and navigator {#ariaid-title2}

Access the MITRE-ATT\&CK heat map and navigator so that you can visualize
the matrix that enables you to use ATT\&CK.

### Before you begin

Role required: sn_ti.read, sn_ti.mitre_analyst

### About this task

You can review the heat map, use the filters to correlate, and perform link analysis of MITRE-ATT\&CK information, the observables, and the security incidents in your organization.

### Procedure

1. Navigate to AllThreat IntelligenceMITRE ATT\&CK RepositoryHeatmap and Navigator.  
   The heat map and navigator open in a new tab.
2. Select the source to populate the heat map.  
   Note:  
   Only the [collections](https://servicenow-prod.fluidtopics.net/DkyFoDNwx7iZVd1RVeX_wQ "Activate the MITRE-ATT&CK profile, and set up a scheduled job so that you can set up MITRE-ATT&CK collections for threat detection in your organization.") and [matrices](https://servicenow-prod.fluidtopics.net/nqPLEJR05m9vu0rz9SesIA "Manage the matrices that have been imported from the MITRE TAXII collections. Matrices are a collection of tactics and techniques. You can view the matrices to review if your collections are available in the MITRE-ATT&CK repository.") that have been activated appear in the source list.

   In the following illustration, you see how to navigate to the heat map and navigator, and how to select the source, which is Enterprise ATT\&CK in this example.
3. Use the search box to quickly find a particular tactic or technique by using its name or ID.  
   The following illustration shows how to search for a tactic, technique, or any information that is contained in them.
4. Click Filters and select a filter from the [Primary](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#primary-heatmap-and-navigator-filters "Use the primary filters to filter techniques in the MITRE-ATT&CK navigator. The information in the MITRE-ATT&CK repository is available for selection.") or [Advanced](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#advanced-heatmap-and-navigator-features "You can use a heat map with advanced filters to perform an analysis by correlating security incidents with MITRE-ATT&CK information.") filters.
5. Click Apply and control the filters as follows:  
   * To save your filters, [create a
     custom view](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#using-the-custom-views "Custom views in the MITRE-ATT&CK heat map and navigator help you to save and view your favorite filters the next time that you land on the heat map."). You can create and save three [custom
     views](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#using-the-custom-views "Custom views in the MITRE-ATT&CK heat map and navigator help you to save and view your favorite filters the next time that you land on the heat map.").
   * To remove the selected filters, click Restore Default Filters to load your default saved view.
   * To clear all filters and your existing view, click Clear all filters.

   {#view-mitre-heat-map__ul_py5_rzf_xnb}  
   Note:  
   The views that you save are specific for a user.
6. Click Hide Sub-Techniques to remove all sub-techniques from the heatmap view.  
   If a technique has sub-techniques, you can click the expand icon to view the sub-techniques.

## Using the custom views {#ariaid-title3}

Custom views in the MITRE-ATT\&CK heat map and navigator help you to save and
view your favorite filters the next time that you land on the heat map.  
Note:  
You can create and save three custom views for every MITRE-ATT\&CK collection per user.

### Create a view {#using-the-custom-views__section_kq3_vxl_vrb}

Once you select the required filters from the [Primary](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#primary-heatmap-and-navigator-filters "Use the primary filters to filter techniques in the MITRE-ATT&CK navigator. The information in the MITRE-ATT&CK repository is available for selection.") or
[Advanced](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#advanced-heatmap-and-navigator-features "You can use a heat map with advanced filters to perform an analysis by correlating security incidents with MITRE-ATT&CK information.") filters, click the ellipsis (...) button on the Filters header and select
Create a new view. Enter the custom view name and Save View.

### Default views {#using-the-custom-views__section_cy5_q4t_vrb}

Click Save this as a default view to directly load the view the next time that you land on the heat map. You can set a default view for each of the collections.  
Note:  
If you are upgrading the Threat Intelligence plugin from an older version, then your existing default view from the old version appears as a custom view.

<br />

### Update a view {#using-the-custom-views__section_hcz_vxl_vrb}

You can make updates to an existing custom view by modifying the required [Primary](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#primary-heatmap-and-navigator-filters "Use the primary filters to filter techniques in the MITRE-ATT&CK navigator. The information in the MITRE-ATT&CK repository is available for selection.") or [Advanced](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#advanced-heatmap-and-navigator-features "You can use a heat map with advanced filters to perform an analysis by correlating security incidents with MITRE-ATT&CK information.") filters. Select a custom view, update the filters as required, and then click the ellipsis (...) button on the Filters header and select Update view to save the filters.

<br />

### Manage custom views {#using-the-custom-views__section_ahq_byl_vrb}

Use the checkboxes next to each custom view to apply the selected custom view filter.  
Click the ellipsis (...) button next to each custom view name to control the custom views as follows:

* Set a default view.
* Remove a custom view as the default view. This doesn't delete the custom view.
* Rename the custom view.
* Delete the custom view.
{#using-the-custom-views__ul_fm2_nbn_vrb}

<br />

### Export a saved view {#using-the-custom-views__section_x5z_wxl_vrb}

To export the saved custom views to JSON files, click ellipsis (...) on the Filters header and select Export saved views. Click the download icon for the custom view you wish to download to your local
computer.

<br />

### Import a view {#using-the-custom-views__section_hqn_yxl_vrb}

You can import only JSON files. To import the custom views, click the ellipsis (...) button on the Filters header and select Import view(json).  
Review the following conditions when importing views:

* You can only import JSON file format.
* You can import only one view or file at a time.
* You cannot import if you already have three custom views in your filters. Delete a custom view and import a view.
* You cannot import a view with an existing custom view name. Rename a view before you import.
{#using-the-custom-views__ul_wl3_c5t_vrb}

<br />

## Navigator with primary filters {#ariaid-title4}

Use the primary filters to filter techniques in the MITRE-ATT\&CK navigator.
The information in the MITRE-ATT\&CK repository is available for
selection.
{#primary-heatmap-and-navigator-filters__table_g35_5fc_xnb__entry__2}

| Filter | Description |
|-|-|
| Adversary Group (Threat Group) | Sets of related intrusion activity that are tracked by a common name in the security community. Groups can mean various threat groups, activity groups, threat actors, intrusion sets, and campaigns. You can add multiple groups to the Adversary Group (Threat Group) filter. For example, you add APT1 and AT12 as both are threat groups that are attributed to China. While both groups might target different sources, they could use similar techniques. |
| Tool | Legitimate software that is used by threat actors to perform attacks. You can understand how threat actors execute campaigns if you know how and what tools are used by threat actors. Tools includes both software that is not found on an enterprise system and software that is available as part of an operating system that is already present in an environment such as Microsoft Windows utilities. For example, gsecdump is a publicly available credential dumper that the APTI1 adversary group uses to obtain password hashes and LSA secrets (Local Security Authority) from Microsoft Windows operating systems. |
| Malware | Commercial, custom closed source, or open-source software that is intended to be used for malicious purposes by adversaries. Examples are PlugX, CHOPSTICK, and so on |
| Platform | Tactics and techniques that represent MITRE-ATT\&CK in a particular platform. For example, MITRE-ATT\&CK supports these platforms in the Enterprise ATT\&CK matrix: Microsoft Windows, macOS, Linux, PRE, AWS, GCP, Azure, Azure AD, Office 365, SaaS, Network. |
| Data source | Data sources that you are collecting in your environment and using to detect MITRE-ATT\&CK techniques. Examples are DLL monitoring, and browser extensions. |
[ ]

{#primary-heatmap-and-navigator-filters__table_g35_5fc_xnb}  
The following illustration shows all the primary filters available in the MITRE-ATT\&CK navigator.

## Using a heat map with primary and advanced features {#ariaid-title5}

You can use a heat map with advanced filters to perform an analysis by correlating
security incidents with MITRE-ATT\&CK information.

### View technique IDs {#advanced-heatmap-and-navigator-features__section_s1k_v5g_xnb}

You can view the MITRE-ATT\&CK technique IDs with the technique names when you
select the Display technique IDs filter.

### View relevant techniques by priority {#advanced-heatmap-and-navigator-features__section_vt3_tvt_vrb}

To filter the techniques based on their relevant priority in the navigator, select Filter by technique relevant priority filter and select the Relevant Priority from the menu. You can
assign multiple priorities for filtering. You can also point to the techniques in the heat map to know the priority of the technique.

The relevant priority information is based on the prioritization you have set in the [Techniques](https://servicenow-prod.fluidtopics.net/URqi74GKQuqG2o8b0MGIfQ "Manage the techniques that have been imported from the MITRE TAXII collections. The techniques contain various ways attackers have developed to employ a given tactic. You can review and deactivate techniques that are not relevant to your organization. In STIX, techniques are known as attack patterns.") relevant priority field.

### View technique detection coverage {#advanced-heatmap-and-navigator-features__section_v1g_w5g_xnb}

To view the overall technique detection coverage in the heat map, select the Display technique detection coverage filter. The heat map highlights the visual spectrum of the detection coverage including the
blind spots where you don't have any coverage. The base system scoring definition and the colors have been defined in the [technique detection coverage](https://servicenow-prod.fluidtopics.net/wMgtrKZmGQlrO2ToDaEeIg "Define the technique detection coverage that your organization must measure and detect specific adversary techniques."). The information has been auto-extracted from the overall technique detection coverage.

For example, areas of the heat map that are marked in red indicate a lack of detection.
Areas that are marked in blue indicate the presence of full detection capabilities. Areas
that are marked in orange, yellow, and light blue reflect partial detection
capabilities.  
* The color visualization is based on the [technique definition and
  color coding](https://servicenow-prod.fluidtopics.net/wMgtrKZmGQlrO2ToDaEeIg "Define the technique detection coverage that your organization must measure and detect specific adversary techniques.") that you define.
* The coverage visualization is based on the [technique detection coverage
  mapping](https://servicenow-prod.fluidtopics.net/5tLotF08usuUwSe~1xicBw "Map your overall technique detection coverage with the technique that enables your organization to detect specific adversary techniques.") that you define.
* If you modify the base system coverage definition, the Coverage Type icons don't display with the techniques in the heat map.  
  Note:  
  The heat map works as expected when you modify the same fields as the base system's-defined technique detection coverage and coverage colors.
{#advanced-heatmap-and-navigator-features__ul_ry5_kch_xnb}

In this illustration, you see the technique detection coverage for all the techniques and
sub-techniques and the coverage type with their colors and icons.

### View technique mitigation coverage {#advanced-heatmap-and-navigator-features__section_ff4_wvt_vrb}

To view the overall technique mitigation coverage in the heat map, select the Display technique mitigation coverage filter. The heat map highlights the visual spectrum of the mitigation coverage including areas that you don't have
any coverage. The mitigation coverage, colors, and percentage ranges have been defined in the [Mitigation Coverage Definition](https://servicenow-prod.fluidtopics.net/cOumO8VHWwn9aRq2oiVEsg "Define the mitigation coverage for each mitigation that is associated with a technique so that you gain visibility into how well your organization can prevent the attacks that happen due to a particular technique."). The information is extracted from the [Overall Technique Mitigation Coverage](https://servicenow-prod.fluidtopics.net/~KfHVAvERc~BbPpafZ2u6A "Map your mitigation coverage with the technique that enables you to detect your organization's overall mitigation strategy.").  
For example, techniques highlighted in red indicate no mitigation coverage, orange indicates poor mitigate coverage, and blue indicate excellent mitigation coverage.

* The color visualization is based on the [technique mitigation definition and color coding](https://servicenow-prod.fluidtopics.net/cOumO8VHWwn9aRq2oiVEsg "Define the mitigation coverage for each mitigation that is associated with a technique so that you gain visibility into how well your organization can prevent the attacks that happen due to a particular technique.") that you define.
* The coverage visualization is based on the [technique mitigation coverage mapping](https://servicenow-prod.fluidtopics.net/~KfHVAvERc~BbPpafZ2u6A "Map your mitigation coverage with the technique that enables you to detect your organization's overall mitigation strategy.") that you define.
* If you modify the base system mitigation coverage definition, the Mitigation Coverage Type icons don't display with the techniques in the heat map.  
  Note:  
  The heat map works as expected when you modify the same fields as the base system's-defined technique mitigation coverage and coverage colors.
{#advanced-heatmap-and-navigator-features__ul_hgm_3w5_vrb}

### View detection and mitigation coverage {#advanced-heatmap-and-navigator-features__section_zkv_wrb_wrb}

Combine the technique detection and mitigation coverage filters. This reveals which techniques are most relevant to your organization.

### View threat group {#advanced-heatmap-and-navigator-features__section_lxx_xvt_vrb}

To view the threat group to technique information on the heat map, select Display threat group heat map. You can measure the number of threat groups that are using a particular technique. The probability of
an attack using a particular technique increases when you have a high number of attackers. The threat group ranges, and heat map colors have been defined in the [Threat Group-Technique Heat Map Definition](https://servicenow-prod.fluidtopics.net/Pouuzd3NKXasb4VDiA4VFg "Define the threat group to technique heatmap definition so that on the heatmap you can measure and detect the attack patterns that threat groups are using to attack your organization. The probability of an attack using a particular technique increases when you have a high number of attackers.").

* The color visualization for the heat map and text is based on the [threat group to technique heatmap definition](https://servicenow-prod.fluidtopics.net/Pouuzd3NKXasb4VDiA4VFg "Define the threat group to technique heatmap definition so that on the heatmap you can measure and detect the attack patterns that threat groups are using to attack your organization. The probability of an attack using a particular technique increases when you have a high number of attackers.").
* The threat group range visualization is based on the [threat group to technique mapping](https://servicenow-prod.fluidtopics.net/qMO804KmsMc24O~FOgFztA "Review the threat group and techniques object to object relationship mapping information that is imported from the MITRE TAXII collections. This mapping enables you to view the technique group and the corresponding technique mapping.").
* You can't use the Display threat group heat map filter when the technique detection coverage or technique mitigation coverage are enabled.
{#advanced-heatmap-and-navigator-features__ul_w1q_vz5_vrb}

### View Security incidents associated with technique {#advanced-heatmap-and-navigator-features__section_hhv_w5g_xnb}

To view the techniques that are frequently exploited in your organization and that have resulted in security incidents, select Display security incident associated with technique. You can view more
information about each of the associated security incidents when you select the link that open in a new window for analysis.  
* Priority: Select Security Incident Priority to filter by the security incident priority.
* Date range: Select the Security Incident Date Range to filter security issues by the date range.
* False positives: Select Filter false positives security incident to remove false positive issues. Selecting this filter reduces the number of security incidents you see in the heat map.
{#advanced-heatmap-and-navigator-features__ul_bsx_bgl_xnb}

Using this with Display technique detection coverage provides an insight into the relevance of the technique detection coverage for your organization until the selected date.

For example, when you turn on both filters, you can see that under the Defense Evasion
tactic, the Masquerading technique has no coverage. When you look further, the Masquerading
technique is related to the Masquerade Task or Service, which also has a security incident
that is associated with it. This shows that there is a gap in the technique detection
coverage for the Masquerading technique and you may want to revise the overall technique
detection coverage.

### View detection rules {#advanced-heatmap-and-navigator-features__section_kwj_x5g_xnb}

To view if you have the detection rules defined for a particular technique, select Display detection rules. You can also see each associated detection rule with their definition.

This information is based on the [detection rules mapping](https://servicenow-prod.fluidtopics.net/qD~SsB2~IecGS5HEUqb_ew "Create detection rules and map them against the tactics and techniques. With this mapping, you can see the coverage for the detection rules in your organization.") that you have defined.

### View CVEs associated with technique {#advanced-heatmap-and-navigator-features__section_bmh_y5g_xnb}

To view the Common Vulnerabilities and Exposures (CVE) information that is associated with each of the techniques, select Display CVEs associated with technique. The CVE to technique information is based on
the information available in the [CVE - Technique Mapping module](https://servicenow-prod.fluidtopics.net/CXyBuH8ecAfPn2osA1rpVg "Manage the CVE and technique information that is mapped after you import the MITRE TAXII collections."). This provides you insight into known vulnerabilities and lets you know if adversaries can potentially exploit your organization.  
Important:  
The heat map is enhanced to display only the relevant CVEs that is associated with the VITs

To view VITs associated with CVEs and techniques, select Display VITs associated with CVE and techniques. Additionally, to further filter techniques without VITs, select Hide techniques without VITs. The CVE and VIT information you view is fetched from the Vulnerability Response product in your environment. You can view the filtered list of CVEs and VITs in the heat map and navigate to each CVE or VIT for every technique from the heat map.

The following describes the relationships between CVEs, VITs, TPEs, and ATT\&CK techniques:

* **CVE to Technique (Many-to-Many)**: A single CVE can be exploited by multiple ATT\&CK techniques, and a single technique can exploit multiple CVEs. This mapping is stored in the CVE - Technique Mapping table.
* **TPE to CVE (Many-to-Many)**: A Third Party Entry (vulnerability advisory) can reference multiple CVEs, and a single CVE can appear in multiple TPEs from different sources.
* **VIT to TPE (Many-to-One)**: Each Vulnerable Item is linked to one TPE. A single TPE can have many VITs, one per affected asset where the vulnerability is detected.
* **VIT to Technique (Many-to-Many, derived)**: A single VIT can relate to multiple techniques, and a technique can relate to many VITs. The MITRE ATT\&CK Technique-CVE-VIT Count view aggregates this data to show the number of CVEs and VITs associated with each technique.

{#advanced-heatmap-and-navigator-features__ul_cve_vit_tid_tpe_rel}  
Note:  
* The Display CVEs associated with technique is available only when the Vulnerability Response product is installed in your environment.
* The VIT and CVE information is calculated based on the scheduled job you set in the [MITRE-ATT\&CK properties](https://servicenow-prod.fluidtopics.net/w1Vgqo6m4i9ZMj1HsMRQkg "Review the MITRE-ATT&CK system property values."). The base system schedule job is set for 24 hours.
{#advanced-heatmap-and-navigator-features__ul_ey5_ssw_vrb}

When you use this filter with the Display security incident associated with technique filter, you can learn if the known vulnerabilities have caused security incidents in your organization.

You can view more information about each CVE to analyze if the CVE is relevant to your organization. To do so, view the vulnerability items. If vulnerability items are created, you can view more information about any associated CI
information in the Vulnerability Response module. You can also review the severity and priority to make informed decisions.

### Analyze Security Incidents {#advanced-heatmap-and-navigator-features__section_xqt_y5g_xnb}

To analyze security incidents and review the techniques that are used by an adversary for an attack, select Analyze Security Incidents. You can add multiple security incidents for analysis by using
comma-separated strings.

This filter helps you to analyze a security incident. Why the incident occurred, what techniques were exploited, if any known threat actors were involved, if the threat actors used a particular sequence for an attack, and so on.
Because you can analyze multiple security incidents at the same time, you can correlate the information to see if they are related or if they are an isolated incident. If the security incidents are related and you observe a pattern,
you can review their progress on the kill chain to stop the attack or to form a defense strategy for your organization.

When you use Analyze Security Incidents with primary filters, such as Adversary Group, you can correlate if known adversaries are involved. For example, when multiple security
incidents are being analyzed, the techniques that are associated with the security incidents are present in the form of a kill chain. As you overlap the information with the adversary, you will notice an overlap between the
techniques that are associated with the security incident and the techniques that are associated with the adversary. Only the overlapped technique information is shown if both filters are enabled.

### Using overlay to analyze security incidents and adversary groups {#advanced-heatmap-and-navigator-features__section_qxb_1wt_vrb}

Use the Enable Overlay / Analyze filter to view the adversary behaviour and analyze one or more of the security incidents and correlate the information to see if an attack is an isolated incident or a
coordinated attack by a known adversary.

For example, you can now view the security incidents and the threat adversary kill chain behaviour in the same view. This view provides overlap information which informs you of the attack and the known adversary behaviour. This
enables you to analyze if this is an isolated attack or a coordinated attack by a known adversary.

Enabling the overlay analyze filter ignores all the primary filters except the Adversary group filter, and ignores the advanced filter Filter by technique relevant priority while
generating a view.  
Once you enable the overlay analyze filter, use the color palette to assign colors for the following:

* Analyze Security Incident
* Adversary Group
* Overlay
{#advanced-heatmap-and-navigator-features__ul_lx3_r2x_vrb}

*[\>]: and then


