Skip to main content

Attack Pattern Data Model

The Attack Technique data model describes the patterns of attack employed by adversaries to exploit known weaknesses in cyber-enabled capabilities. It extends the Entity model data model.

The following table details the default attributes of the Attack Technique data model:

Attribute NameAttribute TypeRelationship TypeRequired
abstractionTextN/ANo
attackPatternsReference (Attack pattern)IS_RELATEDNo
categoriesText (Multivalued)N/ANo
connectorCategoriesText (Multivalued)N/ANo
connectorNamesText (Multivalued)N/ANo
consequencesTextN/ANo
createdByTextN/ANo
dataIntegrationTitlesText (Multivalued)N/ANo
dataModelNameCalculated (Text)N/ANo
dateCreatedDate TimeN/ANo
descriptionText AreaN/ANo
detectionTextN/ANo
displayNameCalculated (Text)N/AYes
executionFlowTextN/ANo
flowStateTextN/ANo
indicatorsTextN/ANo
lastUpdatedDate TimeN/ANo
lifecycleInactiveDateDate TimeN/ANo
lifecyclePurgeDateDate TimeN/ANo
lifecycleStatusSingle ChoiceN/ANo
likelihoodOfAttackTextN/ANo
mitigationsTextN/ANo
nameTextN/ANo
prerequisitesTextN/ANo
resourcesRequiredTextN/ANo
skillsRequiredTextN/ANo
sourceStatusTextN/ANo
sourceUidsText (Multivalued)N/ANo
sourcesReference (Source model)SOURCED_FROMNo
sourcesIconsSource data models iconsN/ANo
summaryTextN/ANo
typicalSeverityTextN/ANo
uidTextN/AYes
updatedByTextN/ANo
urlTextN/ANo
weaknessesReference (Weakness)EXPLOITSNo
FOOTNOTES
  • The attribute names are used in Brinqa Query Language (BQL) queries and Brinqa Condition Language (BCL) predicates.
  • In the Type column, Calculated means that the value of the attribute is computed by executing a script. The text in the parentheses after Calculated denotes the type of the outcome. For additional information, see Calculated attributes.
  • In the Type column, Reference means that two data models are related. The name in the parentheses after Reference indicates the other data model.
  • The Relationship Type column only applies to the Category and Reference type attributes. You can use the relationship type keyword in BQL queries.