Skip to main content

Attack Technique Data Model

The Attack Technique data model describes the methods and tactics utilized by adversaries in various stages of cyber attacks. It extends the Entity model data model.

The following table details the default attributes of the Attack Technique data model:

Attribute NameAttribute TypeRelationship TypeRequired
attackTacticsReference (Attack tactic)USESNo
attackTechniquesReference (Attack technique)ISNo
categoriesText (Multivalued)N/ANo
connectorCategoriesText (Multivalued)N/ANo
connectorNamesText (Multivalued)N/ANo
createdByTextN/ANo
dataIntegrationTitlesText (Multivalued)N/ANo
dataModelNameCalculated (Text)N/ANo
dateCreatedDate TimeN/ANo
defensesBypassedTextN/ANo
descriptionText AreaN/ANo
detectionTextN/ANo
displayNameCalculated (Text)N/AYes
domainTextN/ANo
effectivePermissionsText (Multivalued)N/ANo
flowStateTextN/ANo
impactTypeTextN/ANo
lastUpdatedDate TimeN/ANo
lifecycleInactiveDateDate TimeN/ANo
lifecyclePurgeDateDate TimeN/ANo
lifecycleStatusSingle ChoiceN/ANo
nameTextN/ANo
permissionsRequiredTextN/ANo
platformsText (Multivalued)N/ANo
revisionTextN/ANo
sourceCreatedDateDate TimeN/ANo
sourceLastModifiedDate TimeN/ANo
sourceStatusTextN/ANo
sourceUidsText (Multivalued)N/ANo
sourcesReference (Source model)SOURCED_FROMNo
sourcesIconsSource data models iconsN/ANo
summaryTextN/ANo
uidTextN/AYes
updatedByTextN/ANo
urlTextN/ANo
FOOTNOTES
  • The attribute names are used in Brinqa Query Language (BQL) queries and Brinqa Condition Language (BCL) predicates.
  • In the Type column, Calculated means that the value of the attribute is computed by executing a script. The text in the parentheses after Calculated denotes the type of the outcome. For additional information, see Calculated attributes.
  • In the Type column, Reference means that two data models are related. The name in the parentheses after Reference indicates the other data model.
  • The Relationship Type column only applies to the Category and Reference type attributes. You can use the relationship type keyword in BQL queries.