Commit Graph

20 Commits

Author SHA1 Message Date
Ricardo Dias 7f3adb1508 resources renamed to references 2020-02-08 23:11:32 +00:00
Ricardo Dias 2148e2a686 yaml proof of concept 2020-02-07 18:10:32 +00:00
Nate Guagenti 0cbc54b51e Schema & Data Dictionary Additions & Cleanup (#70)
* define flow to point to correct schemas

* make values code style

* add definitions of ambiguity for url/http

* stage TLS

* just domain

* correct domain terminology to match current OSSEM as well as HELK



* define community id to match HELK.  layer7 and layer 3 implementation

* add PR from https://github.com/hunters-forge/OSSEM/pull/54

* update destination further, especially with dst_host_name and hostname vs fqdn vs domain

* documentation/information to delineate domain vs fqdn vs hostname

* update to support dst_host_name

* make implementation intro more clear

* small url schema verbiage updates

* still staging, but cleanup verbiage for now

* toward dns

* host_name schema for searching all

* towards event

* create etl schema

* staging host name (domain) enrichment


* correct flow from master branch

* not necessary to revert lowercase


* update url_host_name


* markdown cleanup

* match guid names

* add link names/paths that are in data dictionaries

 filename

* correct AccessReason

* add application generated auditing

* add 4907

* add event XML

* add event XML



* add 4670

* missing AccessReason

* fix SD naming

* match CIM for src and dst ip addresses

* add 4696 xml

* process cleanups, corrections, and HELK<>OSSEM

* add 4797

* add sysmon 255

* update match HELK

* - [x] group schema (name, domain, sid, etc)
- [x] Audit Security Group Management
    - [x] Security:4727
    - [x] Security:4728
    - [x] Security:4729
    - [x] Security:4730
    - [x] Security:4731
    - [x] Security:4732
    - [x] Security:4733
    - [x] Security:4734
    - [x] Security:4735
    - [x] Security:4737
    - [x] Security:4754
    - [x] Security:4755
    - [x] Security:4756
    - [x] Security:4757
    - [x] Security:4758
    - [x] Security:4764
    - [x] Security:4799

* update .gitignore

* begin adding zeek data dictionaries

* begin adding zeek data dictionaries

* begin adding zeek data dictionaries

* begin adding zeek data dictionaries

* JSpieldenner Moving Forward

* JS102919

* JS102519

* match SidHistory for group to be group_sid_history

* Audit Distribution Group Management

* begin adding zeek data dictionaries



* add VLANs

* add event duration for length of time/event

* add network history/connection states

* complete zeek conn log

* set network protocols

* complete zeek conn log

* zeek event_uid and network proto

* zeek progress on DHCP

* event uid

* duplicate line

* add 4670 from main and fix typo and field to what helk has

 for logon_transmitted_services

* use current reporter logon id field, pending confirmation until then

* field type is string NOT ip

* add 4649

* correct field names. update description and correct ordering of reference

* update description and correct ordering of reference

* correct minimum OS, fix and add relative paths

* DnsName to dst_host_name, fix multiple typo's and update description and correct ordering of reference

* correct session id field name. also typo

* conform with similar field types.. like UPN to user_identity. also update description

* add 4825, even though not on microsoft's website :)

* field name typos and update field descriptions a bit

* finish Account Logon/Other Logon/Logoff

* fix typo, update description and match to HELK https://github.com/Cyb3rWard0g/HELK/issues/314

* fill out the rest for object/registry

* update all Zeek categories' descriptions/README's.

* schema

* zeek log examples

* finish dns schema

* add dhcp ip

* finish dns schema

* finish schema

* add user_password

* update etl schema

* forward http

* add src/dst file info



* add ja3/ja3s

* forward ssl/tls

* update example

 in "task"

* event example json cleanup

* TransactionId should be transaction_guid

* readme ordering

* missing Service standardized field name

* correct description

* correct object_access_mask value type

* correct object_access_list value type to string

* correct descriptions

* add event id 4659

* add event id 4665, 4666, 4667, 4668

* add event id 5051

* fix relative path links

* directory service changes HELK <> OSSEM

* add network_direction

* HELK <> OSSEM

* scheduled tasks HELK <> OSSEM

* network_direction

* add etl_versioning

* because potential of 3 process ID's, note field just in case

* HELK <> OSSEM user_target_ is target_user_

* directory service object HELK <> OSSEM

* HELK <> OSSEM audit policy change

* 4777

* add 4774 and  4775

* HELK <> OSSEM dpapi

* clean, add error and status codes and network application name



* forward movement

* finish the start of HTTP schema



* hex as string, identify decimal separately

* add sha512 hash

* begin adding x509/certificate info for tls/signed things



* Combine Kerberos TGS and AS as one such a lot of overlap and makes for a better schema
2020-01-31 23:59:21 -05:00
Ricardo Dias addbada963 Update object_relationships.md
Renamed 'win registry' data objects to 'registry'.
2020-01-22 16:49:23 +00:00
Roberto Rodriguez ec204f2517 Merge pull request #65 from hxnoyd/ddm_kerberos
updated kerberos entity names
2019-11-30 22:47:52 -05:00
Ricardo Dias ac6e46b072 updated registry entity names 2019-11-30 01:09:52 +00:00
Ricardo Dias 4cd4ff3085 updated kerberos entity names 2019-11-30 00:57:06 +00:00
Roberto Rodriguez acd8815252 Updated Sysmon Dictionaries V9.0.1
- New Images
- Updated XML sample
- Manifest Schema version 4.2
2019-04-26 21:24:36 -04:00
Roberto Rodriguez f98ed70825 Merge pull request #17 from jaredcatkinson/master
Added the relationships from the attackcon google sheet as markdown table
2018-11-01 18:12:47 -04:00
Jared Atkinson fe13744ef4 Added the relationships from the attackcon google sheet as markdown tabl 2018-11-01 18:09:17 -04:00
Roberto Rodriguez 85c5580b5b Updated Data Model & Data Dictionaries
- Added Jared as a contributor
- Updated Security Event 4656. Name was wrong
- Updated Win Registry name
2018-10-29 10:56:23 -04:00
José Luis Rodríguez 5683a50582 ATT&CKcon 2018 2018-10-24 17:57:29 -04:00
grogsaxle c45783c621 remove _number from port fields 2018-06-07 06:22:37 -05:00
bfuzzy 79bb127e78 added registry_key_new_name 2018-05-24 15:09:56 -04:00
bfuzzy 5d31cc43cf registry objects 2018-05-24 09:38:02 -04:00
bfuzzy f9b05562d3 Update powershell.md 2018-05-22 12:18:04 -04:00
bfuzzy bbd082dfaf added powershell w/o descriptions 2018-05-22 11:21:07 -04:00
Roberto Rodriguez f24f117be5 051718 2018-05-17 11:39:12 -04:00
Roberto Rodriguez 802f1de58d 051718 2018-05-17 10:11:51 -04:00
Roberto Rodriguez 1675d9fa0b 051618 2018-05-16 19:30:03 -04:00