SOLVED

Mitre link from Sentinel into Service Now

%3CLINGO-SUB%20id%3D%22lingo-sub-2544172%22%20slang%3D%22en-US%22%3EMitre%20link%20from%20Sentinel%20into%20Service%20Now%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2544172%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20wondering%20before%20I%20start%20work%20on%20it%20whether%20anyone%20has%20built%20or%20is%20looking%20to%20build%20Mitre%20framework%20correlation%20of%20Tactics%20and%20Techniques%20from%20Sentinel%20into%20SIR%20ServiceNow.%20%26nbsp%3B%20I%20can%20see%20how%20it%20is%20possible%20to%20map%20out%20the%20Tactics%20that%20flow%20through%20into%20Sentinel%20-%20however%20the%20Techniques%20(such%20as%20phishing%20(Technique)%20sits%20behind%20the%20Initial%20Access%20(Tactic).%20%26nbsp%3BWanting%20to%20be%20able%20to%20just%20do%20this%20at%20that%20high%20level%20so%20it%20hit%20and%20correlates%20to%20the%20Category%20and%20Sub-Category%20in%20SIR%20ServiceNow.%20%26nbsp%3B%20I%20can%20see%20how%20the%20Mitre%20workbook%20looks%20up%20against%20the%20populating%20github%20page%20-%20but%20trying%20to%20populate%20the%20techniques%20looks%20to%20be%20slightly%20more%20complicated%20with%20initial%20thoughts%20being%20a%20look%20up%20against%20something%20-%20pull%20the%20rule%20name%20and%20cross%20link%20that.%20%26nbsp%3BAny%20thoughts%20or%20ideas%20always%20welcome.%20%26nbsp%3B%20Thanks%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2545830%22%20slang%3D%22en-US%22%3ERe%3A%20Mitre%20link%20from%20Sentinel%20into%20Service%20Now%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2545830%22%20slang%3D%22en-US%22%3EYou%20can%20extend%20the%20Workbook%20query%20to%20also%20lookup%20the%20Techniques%20as%20well%20as%20the%20Tactics%20per%20Rule.%3CBR%20%2F%3E%3CBR%20%2F%3Elet%20SentinelGithub%20%3D%20(externaldata(MITREMatrix%3A%20string%2C%20Tactic%3A%20string%2C%20TechniqueId%3Astring%2C%20TechniqueName%3Astring%2C%20Platform%3A%20string%20%2C%20DetectionType%3A%20string%20%2C%20DetectionService%3A%20string%20%2C%20DetectionId%3A%20string%2C%20DetectionName%3A%20string%2C%20DetectionDescription%3A%20string%2C%20ConnectorId%3A%20string%2C%20DataTypes%3A%20string%2C%20Query%3A%20string%20%2C%20QueryFrequency%3A%20string%20%2C%20QueryPeriod%3Astring%20%2C%20TriggerOperator%3A%20string%2C%20TriggerThreshold%3A%20string%2C%20DetectionSeverity%3A%20string%2C%20DetctionUrl%3A%20string%2C%20IngestedDate%3A%20string%20)%3CBR%20%2F%3E%5B%40%22%3CA%20href%3D%22https%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSample%2520Data%2FMITRE%2520ATT%2526CK%2FAzureSentinel.csv%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fraw.githubusercontent.com%2FAzure%2FAzure-Sentinel%2Fmaster%2FSample%2520Data%2FMITRE%2520ATT%2526CK%2FAzureSentinel.csv%3C%2FA%3E%22%5D%3CBR%20%2F%3E)%3B%3CBR%20%2F%3ESentinelGithub%3CBR%20%2F%3E%7C%20where%20isnotempty(Tactic)%3CBR%20%2F%3E%7C%20summarize%20make_set(TechniqueId)%2C%20make_set(Tactic)%20by%20DetectionName%2C%20DetectionDescription%2C%20DataTypes%2C%20Query%2C%20DetctionUrl%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi all 

 

I am wondering before I start work on it whether anyone has built or is looking to build Mitre framework correlation of Tactics and Techniques from Sentinel into SIR ServiceNow.   I can see how it is possible to map out the Tactics that flow through into Sentinel - however the Techniques (such as phishing (Technique) sits behind the Initial Access (Tactic).  Wanting to be able to just do this at that high level so it hit and correlates to the Category and Sub-Category in SIR ServiceNow.   I can see how the Mitre workbook looks up against the populating github page - but trying to populate the techniques looks to be slightly more complicated with initial thoughts being a look up against something - pull the rule name and cross link that.  Any thoughts or ideas always welcome.   Thanks 

2 Replies
best response confirmed by wootts (Occasional Contributor)
Solution
You can extend the Workbook query to also lookup the Techniques as well as the Tactics per Rule.

let SentinelGithub = (externaldata(MITREMatrix: string, Tactic: string, TechniqueId:string, TechniqueName:string, Platform: string , DetectionType: string , DetectionService: string , DetectionId: string, DetectionName: string, DetectionDescription: string, ConnectorId: string, DataTypes: string, Query: string , QueryFrequency: string , QueryPeriod:string , TriggerOperator: string, TriggerThreshold: string, DetectionSeverity: string, DetctionUrl: string, IngestedDate: string )
[@"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Sample%20Data/MITRE%20ATT%26CK/AzureSe..."]
);
SentinelGithub
| where isnotempty(Tactic)
| summarize make_set(TechniqueId), make_set(Tactic) by DetectionName, DetectionDescription, DataTypes, Query, DetctionUrl
Clive - thanks for taking the time to reply ... will have a look at this now - have a great day