Files
hunters-forge-OSSEM/attack_data_sources
Roberto Rodriguez 4fa41318f4 Updated Notebook Link
2019-06-06 16:06:39 -04:00
..
2018-10-24 17:57:29 -04:00
2019-06-06 16:06:39 -04:00

MITRE ATT&CK

MITREs Adversarial Tactics, Techniques and Common Knowledge (ATT&CK™) is a curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversarys lifecycle and the platforms they are known to target. ATT&CK is useful for understanding security risk against known adversary behavior, for planning security improvements, and verifying defenses work as expected.

Reference: ATTCK

This part of the OSSEM project focuses on the documentation of ATT&CK data sources suggested or associated with techniques defined in the Enterprise Matrix. In addition, here is where ATT&CK data sources will be mapped with specific sub data sources defined in the Detection Data Model with the main goal of creating a link between ATT&CK data sources and event logs.

Data source (Process Monitoring) mapped to specific event logs example:

alt text

Mapping event logs to ATT&CK data sources

The methodology follows the next steps:

  • Exploring ATT&CK data sources
  • Documenting event logs related to ATT&CK data sources
  • Develop a data model
  • Map event logs to ATT&CK data sources

Resources: