/mitre_attack/campaigns

POST /api/mitre_attack/campaigns

Price: 20 credits

Get a MITRE ATT&CK campaign by its ATT&CK id

How to use it

Use this for a named intrusion campaign such as C0022, which is a bounded set of activity with a first- and last-seen window rather than a standing actor. Those two dates are ATT&CK's reading of the public reporting it cites, not an observation window of ours, and the campaign may or may not be attributed to a group — check the campaign's own relationships rather than assuming one.

Parameters

Request body

Response

Errors

Response headers