Skip to content

SEP: atlas tag namespace for MITRE ATLAS technique IDs #219

Description

@Daniel-Andrawis

Author(s)

Daniel Andrawis (@Daniel-Andrawis)

SEP Type

Schema Extensions (logsource categories)

Abstract

Add an atlas tag namespace for MITRE ATLAS.

Problem Statement

I tag Sigma rules with MITRE ATLAS techniques and there's no namespace for it. sigma check rejects atlas.aml.t0051 as an invalid namespace. ATT&CK has no technique for prompt injection, so attack.* only gets me to a tactic. The ID ends up in references where no tooling can read it.

Use Cases

Rules covering prompt injection, jailbreak framing, inference-API abuse, or model-output extraction. That's the four I have; ATLAS has 170 techniques so there's a lot more room.

Detailed Specification

One line in sigma-appendix-tags.md under Namespaces:

- atlas: Categorization according to MITRE ATLAS (https://atlas.mitre.org)

Technique tags the same way attack already does it, lowercase and dotted: atlas.aml.t0051 for AML.T0051.

One thing I'm unsure about: whether the tag should be atlas.aml.t0051 or atlas.t0051. ATLAS IDs all carry the AML. prefix, so repeating it is redundant, but dropping it means the tag no longer matches the published ID. I went with keeping it. Happy to be told otherwise.

Syntax Examples

tags:
  - atlas.aml.t0051
  - attack.execution

Backward Compatibility Impact

None, it's additive.

Implementation Areas

sigma-appendix-tags.md, and adding atlas to the namespace allowlist in the pySigma tag validator.

Submitter Checklist

  • Searched for duplicates. No hits for atlas
  • Provided concrete examples and use cases
  • Considered backward compatibility
  • Thought about implementation complexity

Implementation Assistance

I'll open the PR if this seems reasonable.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions