---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set up the MITRE-ATT\&CK framework

# Set up the MITRE-ATT\&CK framework {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Activate the MITRE-ATT\&CK profile, and set up a scheduled job so that you
can set up MITRE-ATT\&CK collections for threat detection in your
organization.

## Before you begin

Role required: sn_ti.admin

## About this task

Structured Threat Information Expression (STIX™) is a language for
describing cyberthreat information in a standardized and structured manner. Using
STIX data and Trusted Automated Exchange of Indicator Information (TAXII™) profiles, security teams can use shared cyberthreat
information to isolate threats that have been previously identified by your company
and from other sources.

## Procedure

1. Navigate to AllThreat IntelligenceSourcesTAXII Profiles.  
   You see the available TAXII profiles.
2. Click the MITRE ATT\&CK profile that is provided with the base system.  

   <br />

3. To activate the TAXII collection, set the Active option to true for the TAXII collection that is relevant to your organization (Enterprise ATT\&CK, Mobile ATT\&CK, or ICS ATT\&CK).  
   {#setup-mitre-profile__table_k13_xlc_znb__entry__2}

   | TAXII collection | Description |
   |-|-|
   | Enterprise ATT\&CK | Describes the behaviors and actions that an adversary takes to compromise and operate in an enterprise network and cloud. Note: The Pre ATT\&CK matrix has been deprecated by MITRE and is merged with the Enterprise matrix. |
   | Mobile ATT\&CK | Describes the adversary behaviors and actions that focus on mobile devices. |
   | ICS ATT\&CK | Describes the actions that an adversary takes while operating within an Industrial Control Systems (ICS) network. |
   [ ]

   {#setup-mitre-profile__table_k13_xlc_znb}
4. To periodically refresh the collection, set the Run option as appropriate for your organization.  
   By default this option is set to On Demand.  
   Note:  
   1. Collections are packaged as part of Threat Intelligence Core plugin. Installing or updating the Threat Intelligence Support Common - Version 12.0 or higher, and Threat Intelligence - Version 12.0 or higher ensures that your collections data is auto-populated.
   2. Activate the TAXII collection only for the collection that you intend to use in your organization and disable the other collections. For example, if you intend to use Enterprise ATT\&CK matrix, then activate Enterprise ATT\&CK at the TAXII collection level and at the [Matrices](https://servicenow-prod.fluidtopics.net/nqPLEJR05m9vu0rz9SesIA "Manage the matrices that have been imported from the MITRE TAXII collections. Matrices are a collection of tactics and techniques. You can view the matrices to review if your collections are available in the MITRE-ATT&CK repository.") level. Disable the other Mobile ATT\&CK and ICS ATT\&CK matrices at the TAXII collection and at the Matrices level.
   3. In the TAXII Collections related lists, if you select the Run option as Daily, then an error occurs and the option defaults to On Demand. This error occurs as scheduling the MITRE-ATT\&CK data refresh daily is restricted to optimize the load on the MITRE servers. Also, MITRE updates the ATT\&CK data only twice a year.
   4. The TAXII collections are not refreshed unless you activate the TAXII collection.
   5. Updates to existing collections can be retrieved from the MITRE server by scheduling the 'run' frequency in each collection.
   6. The customizations that you make to the MITRE-ATT\&CK repository data (Malware, Group, Mitigation, and Tool objects to a technique) are saved during scheduled updates.
   7. MITRE updates the MITRE-ATT\&CK knowledge base where some objects are identified as revoked or deprecated, new objects are added, or existing objects are modified. If MITRE revokes any tactic or technique, then these objects are marked as revoked in the ServiceNow AI Platform. The revoked objects are kept in the repository but are not available for use in the ServiceNow AI Platform.
   {#setup-mitre-profile__ol_xls_k2g_5nb}

## What to do next

After the TAXII profile setup is complete, the MITRE-ATT\&CK repository data is imported at regular intervals to the ServiceNow AI Platform®. You can see this data by navigating to MITRE ATT\&CK RepositoryMatrices and MITRE ATT\&CK RepositoryTechniques.
**Related concepts**   

* [Auto-extract technique rules for importing MITRE-ATT\&CK information](https://servicenow-prod.fluidtopics.net/XoPRv_3BTjVwjxRxeqq~kA#auto-extract-technique-rules "Use the base system auto-extraction rules to import the MITRE-ATT&CK information from any existing third-party integrations.")  
**Related tasks**   

* [Manage matrices](https://servicenow-prod.fluidtopics.net/nqPLEJR05m9vu0rz9SesIA "Manage the matrices that have been imported from the MITRE TAXII collections. Matrices are a collection of tactics and techniques. You can view the matrices to review if your collections are available in the MITRE-ATT&CK repository.")
* [Manage techniques](https://servicenow-prod.fluidtopics.net/URqi74GKQuqG2o8b0MGIfQ "Manage the techniques that have been imported from the MITRE TAXII collections. The techniques contain various ways attackers have developed to employ a given tactic. You can review and deactivate techniques that are not relevant to your organization. In STIX, techniques are known as attack patterns.")
* [Manage mitigations](https://servicenow-prod.fluidtopics.net/FHORn7DFdIWN8bNNU45Nkw "Manage the mitigations that have been imported from the MITRE TAXII collections. Mitigations enable you to prevent an adversary from successfully executing techniques or sub-techniques against your organization. In STIX, mitigations are known as course of actions.")
* [Manage groups](https://servicenow-prod.fluidtopics.net/nP0Q~N7euo3vPOIPN4~QrA "Manage the groups that have been imported from the MITRE TAXII collections. Groups are sets of related intrusion activity that are tracked by a common name in the security community. Analysts track clusters of activities using various terms such as threat groups, activity groups, threat actors, intrusion sets, and campaigns. In STIX, groups are known as intrusion sets.")
* [Manage malware](https://servicenow-prod.fluidtopics.net/rbkPObNj9ZFy5Kd_uAlZIg "Manage the malware information that you imported from the MITRE TAXII collections. Malware is a type of TTP that represents malicious code. It refers to a program that is covertly inserted into a system. The intent of a malware is to compromise the confidentiality, integrity, or availability of the victim's data, applications, or operating system (OS).")
* [Manage tools](https://servicenow-prod.fluidtopics.net/UKS35A1Kvno4Q74JImg1Mw "Manage the tools information that you imported from the MITRE TAXII collections. Tools are legitimate software that are used by threat actors to perform attacks.")
* [Manage MITRE relationships](https://servicenow-prod.fluidtopics.net/9eSBbUwmy_Yj6DDKQhgE2w "Manage the MITRE relationships information that you imported from the MITRE TAXII collections.")
* [Manage CVE and technique mapping](https://servicenow-prod.fluidtopics.net/CXyBuH8ecAfPn2osA1rpVg "Manage the CVE and technique information that is mapped after you import the MITRE TAXII collections.")
* [Extend the MITRE-ATT\&CK data](https://servicenow-prod.fluidtopics.net/dT~jSmz3KJa2ydCaIr2maQ "Extend the MITRE-ATT&CK repository data in the ServiceNow AI Platform by enriching it.")
* [Define the data source and detection tool mapping](https://servicenow-prod.fluidtopics.net/8Bxv6AdV4u_9vH97oJphmQ "Define the data source and detection tool mapping for MITRE-ATT&CK tactics and techniques. The data source mapping provides you with insight into the relevance and availability of the data sources and the detection tools for monitoring the data sources in your environment.")
* [Define the data source and data component mapping](https://servicenow-prod.fluidtopics.net/wgYmS7ALki6yXpfsG71R9Q "Use the Data Component Mapping if you are using the latest TAXII collections, and you want to maintain a relationship between the data sources, data components, and the various techniques. Map the data sources with the additional context of data components that provides an extra sublayer of context to data sources that enable you to understand adversary behaviors in MITRE-ATT&CK better.")
* [Define the technique detection coverage](https://servicenow-prod.fluidtopics.net/wMgtrKZmGQlrO2ToDaEeIg "Define the technique detection coverage that your organization must measure and detect specific adversary techniques.")
* [Map your technique detection coverage to a technique](https://servicenow-prod.fluidtopics.net/5tLotF08usuUwSe~1xicBw "Map your overall technique detection coverage with the technique that enables your organization to detect specific adversary techniques.")
* [Define the mitigation coverage](https://servicenow-prod.fluidtopics.net/cOumO8VHWwn9aRq2oiVEsg "Define the mitigation coverage for each mitigation that is associated with a technique so that you gain visibility into how well your organization can prevent the attacks that happen due to a particular technique.")
* [Map your mitigation coverage to a technique](https://servicenow-prod.fluidtopics.net/~KfHVAvERc~BbPpafZ2u6A "Map your mitigation coverage with the technique that enables you to detect your organization's overall mitigation strategy.")
* [Create and map detection rules](https://servicenow-prod.fluidtopics.net/qD~SsB2~IecGS5HEUqb_ew "Create detection rules and map them against the tactics and techniques. With this mapping, you can see the coverage for the detection rules in your organization.")
* [Review threat group and MITRE-ATT\&CK techniques mapping](https://servicenow-prod.fluidtopics.net/qMO804KmsMc24O~FOgFztA "Review the threat group and techniques object to object relationship mapping information that is imported from the MITRE TAXII collections. This mapping enables you to view the technique group and the corresponding technique mapping.")
* [Threat group to technique heatmap definition](https://servicenow-prod.fluidtopics.net/Pouuzd3NKXasb4VDiA4VFg "Define the threat group to technique heatmap definition so that on the heatmap you can measure and detect the attack patterns that threat groups are using to attack your organization. The probability of an attack using a particular technique increases when you have a high number of attackers.")
* [Review the MITRE-ATT\&CK system properties](https://servicenow-prod.fluidtopics.net/w1Vgqo6m4i9ZMj1HsMRQkg "Review the MITRE-ATT&CK system property values.")  
**Related reference**   

* [Get started with MITRE-ATT\&CK framework](https://servicenow-prod.fluidtopics.net/T674GxzcCWVAwSySD~RCVg "Review the following information before you start setting up your MITRE-ATT&CK framework.")
* [Understand the MITRE to STIX data model](https://servicenow-prod.fluidtopics.net/R2accBfZZIG7c2SA1cEVyA "Review the terminology used by MITRE and STIX to efficiently use and understand the MITRE-ATT&CK framework in the ServiceNow AI Platform.")
* [Domain separation and MITRE-ATT\&CK](https://servicenow-prod.fluidtopics.net/8fWXWk06IEEEdBrRBFsnrQ "This domain separation overview pertains to MITRE-ATT&CK. Domain separation allows you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.")

*[\>]: and then


