MITRE JSON Parser
Query
No standalone KQL detected in this source
View source on GitHubAbout this query
Explanation
This query retrieves information from MITRE's Enterprise Attack json file and parses it into a format that can be used for analysis.
Details

Rod Trent
Released: April 30, 2024
Tables
MITRE
Keywords
ExternaldataObject_marking_refsIdTypeCreatedCreated_by_refExternal_referencesSource_nameUrlExternal_idModifiedNameDescriptionX_mitre_deprecatedX_mitre_versionX_mitre_modified_by_ref.
Operators
externaldatawithformatingestionMappinglet[ ]@"https://github.com/mitre/cti/blob/master/enterprise-attack/enterprise-attack.json"PathPropertiesColumn$.type$.id$.objects$.objects.x_mitre_domains$.objects.object_marking_refs$.objects.id$.objects.type$.objects.created$.objects.created_by_ref$.objects.external_references$.objects.external_references.source_name$.objects.external_references.url$.objects.external_references.external_id$.objects.modified$.objects.name$.objects.description$.objects.x_mitre_deprecated$.objects.x_mitre_version$.objects.x_mitre_modified_by_ref