Author(s)
Daniel Andrawis (@Daniel-Andrawis)
SEP Type
Schema Extensions (logsource categories)
Abstract
Add an atlas tag namespace for MITRE ATLAS.
Problem Statement
I tag Sigma rules with MITRE ATLAS techniques and there's no namespace for it. sigma check rejects atlas.aml.t0051 as an invalid namespace. ATT&CK has no technique for prompt injection, so attack.* only gets me to a tactic. The ID ends up in references where no tooling can read it.
Use Cases
Rules covering prompt injection, jailbreak framing, inference-API abuse, or model-output extraction. That's the four I have; ATLAS has 170 techniques so there's a lot more room.
Detailed Specification
One line in sigma-appendix-tags.md under Namespaces:
- atlas: Categorization according to MITRE ATLAS (https://atlas.mitre.org)
Technique tags the same way attack already does it, lowercase and dotted: atlas.aml.t0051 for AML.T0051.
One thing I'm unsure about: whether the tag should be atlas.aml.t0051 or atlas.t0051. ATLAS IDs all carry the AML. prefix, so repeating it is redundant, but dropping it means the tag no longer matches the published ID. I went with keeping it. Happy to be told otherwise.
Syntax Examples
tags:
- atlas.aml.t0051
- attack.execution
Backward Compatibility Impact
None, it's additive.
Implementation Areas
sigma-appendix-tags.md, and adding atlas to the namespace allowlist in the pySigma tag validator.
Submitter Checklist
Implementation Assistance
I'll open the PR if this seems reasonable.
Author(s)
Daniel Andrawis (@Daniel-Andrawis)
SEP Type
Schema Extensions (logsource categories)
Abstract
Add an
atlastag namespace for MITRE ATLAS.Problem Statement
I tag Sigma rules with MITRE ATLAS techniques and there's no namespace for it.
sigma checkrejectsatlas.aml.t0051as an invalid namespace. ATT&CK has no technique for prompt injection, soattack.*only gets me to a tactic. The ID ends up inreferenceswhere no tooling can read it.Use Cases
Rules covering prompt injection, jailbreak framing, inference-API abuse, or model-output extraction. That's the four I have; ATLAS has 170 techniques so there's a lot more room.
Detailed Specification
One line in
sigma-appendix-tags.mdunder Namespaces:Technique tags the same way
attackalready does it, lowercase and dotted:atlas.aml.t0051forAML.T0051.One thing I'm unsure about: whether the tag should be
atlas.aml.t0051oratlas.t0051. ATLAS IDs all carry theAML.prefix, so repeating it is redundant, but dropping it means the tag no longer matches the published ID. I went with keeping it. Happy to be told otherwise.Syntax Examples
Backward Compatibility Impact
None, it's additive.
Implementation Areas
sigma-appendix-tags.md, and addingatlasto the namespace allowlist in the pySigma tag validator.Submitter Checklist
atlasImplementation Assistance
I'll open the PR if this seems reasonable.