mirror of
https://github.com/hunters-forge/OSSEM
synced 2026-06-08 14:44:11 +00:00
19 lines
1.1 KiB
YAML
19 lines
1.1 KiB
YAML
title: MITRE ATT&CK
|
|
description: This part of the OSSEM project focuses on the documentation of ATT&CK
|
|
data sources suggested or associated with techniques defined in the https://attack.mitre.org/wiki/Technique_Matrix.
|
|
In addition, here is where ATT&CK data sources will be mapped with specific
|
|
sub data sources defined in the /detection_data_model with the main goal of creating
|
|
a link between ATT&CK data sources and event logs.
|
|
images:
|
|
- title: Data source (Process Monitoring) mapped to specific event logs example
|
|
source: /resources/images/attck_datasource_eventlogs_example.png
|
|
references:
|
|
- text: Enterprise Matrix
|
|
link: https://attack.mitre.org/wiki/Technique_Matrix
|
|
- text: Jupyter notebook to explore ATT&CK data sources
|
|
link: https://github.com/Cyb3rWard0g/ATTACK-Python-Client/blob/master/notebooks/ATT%26CK_DataSources.ipynb
|
|
- text: ATT&CKcon 2018 - Slides and demos documents
|
|
link: https://github.com/Cyb3rWard0g/presentations/tree/master/ATTACKcon
|
|
- text: ATT&CK Data Sources mapped to Event Logs
|
|
link: https://docs.google.com/spreadsheets/d/1ow7YRDEDJs67kcKMZZ66_5z1ipJry9QrsDQkjQvizJM/edit?usp=sharing
|