- Added Channel field
- Added references (URL) for Security auditing and sysmon events
- did not run python script. Will do after adding channel field for all events
- Updated log_source to Microsoft-Windows-SysmonMicrosoft-Windows-Sysmon
- added channel: Microsoft-Windows-Sysmon/Operational
- Did not run python script. Will do after adding channel field
Removed audit category, log_channel
Changed log_provider for log_source (Match OSSEM-DD)
Using filter_in section to describe the ActionType field
Added event version 1
Solved issue #40 : using script adding_uuid.py, added ids to every relationship
Solved issue #44 : use case mitre --> techniques to event mapping json and yaml only includes techniques with events and it validates if event platform is in technique platforms
Relationships:
- process created file
- process created process
- process executed command
- process modified file
- user created file
- user created process
- user executed command
- user modified file
- Updating ATT&CK data sources and components
- Adding new relationships and events mapping
- Updating Python Script to create Relationships Yaml files