1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
{
"summary": {
"rules_total": 5,
"rules_tagged": 4,
"rules_untagged": 1,
"techniques": 4,
"subtechniques": 2,
"tactics": 2
},
"techniques": [
{
"id": "T1047",
"tactics": [
"execution"
],
"rule_count": 1,
"rules": [
"WMI"
]
},
{
"id": "T1059",
"tactics": [
"execution"
],
"rule_count": 1,
"rules": [
"Cmd"
]
},
{
"id": "T1059.001",
"tactics": [
"execution"
],
"rule_count": 1,
"rules": [
"PowerShell"
]
},
{
"id": "T1218.001",
"tactics": [
"defense-evasion"
],
"rule_count": 1,
"rules": [
"Rundll32"
]
}
],
"untagged_rules": [
"Untagged Rule"
],
"atomics": {
"atomics_total": 4,
"covered": 3,
"atomics_without_rule": [
"T1566"
],
"rules_without_atomic": [
"T1047"
]
},
"baseline": {
"baseline_total": 4,
"covered": 2,
"baseline_not_covered": [
"T1003",
"T1566"
],
"ahead_of_baseline": [
"T1218.001"
]
},
"targets": {
"targets_total": 3,
"covered": 2,
"uncovered": [
"T1003"
],
"covered_via_subtechnique": [
"T1218"
]
}
}