- Added cloud platforms under the enterprise domain:
AWS
,GCP
,Azure
,Office 365
,Azure AD
, andSaaS
.
- Descriptions added to relationships of type
mitigates
under the enterprise domain
x_mitre_impact_type
added for enterprise techniques within theImpact
tactic- Descriptions added to relationships between software/groups
x_mitre_platforms
added for enterprise malware/toolsx_mitre_detection
added to attack-patterns- Custom MITRE attributes removed from descriptions in attack-patterns
- Alias descriptions added for malware/tools/intrusion-sets as external references
- Descriptions added to relationships between groups/attack-patterns in PRE-ATT&CK
- Names of ATT&CK objects replaced in descriptions and x_mitre_detection fields with markdown links
CAPEC ids
added to external references for attack-patterns- Citations in alias descriptions added as external references in the object containing the alias description
- Added
x-mitre-tactic
andx-mitre-matrix
objects - Changed ===Windows=== subheadings to ### Windows subheadings (Windows is just one example)
- Added space between asterisks (ex. *Content to * Content) to populate markdown correctly
- Changed "true" to True in
x_mitre_deprecated
- Added old ATT&CK IDs to Mobile/PRE-ATT&CK objects whose IDs have changed as
x-mitre-old-attack-id