A city CISO asks how Enterprise Security uses MITRE ATT&CK rather than just hanging a poster on the SOC wall. What is the primary mechanism?
Select an answer to reveal the explanation.
Short Explanation
ATT&CK on the wall is a poster; ATT&CK in ES is a tag on the detection. Annotations glue tactic and technique onto correlation searches so the notable and the risk story speak ATT&CK. Splunk does not invent a replacement matrix.
Full Explanation
Enterprise Security incorporates MITRE ATT&CK by annotating detections and correlation searches with tactic and technique. Those annotations travel with notables and risk events so analysts can read a framework-literate story. Splunk does not replace ATT&CK with a CIM data model, and pasting PDF pages into comments is not the product mechanism. Installing reference content without annotated, data-backed detections does not produce coverage.