Giter Club home page Giter Club logo

attack_data's Issues

Splunk prerequisites list for parsing of attack data

I would like to suggest as improvement to add details ( or a file ) with prerequisites for ingesting the attack data in a new Splunk instance. If the data is ingested in the UI using the Add data wizard, the data is not parsed, in order for Sysmon for Windows telemetry to be parsed the Add-on "Splunk Add-on for Sysmon" ( https://splunkbase.splunk.com/app/5709/ ) must be installed.
And attack data like https://github.com/splunk/attack_data/tree/master/datasets/malware/cyclopsblink requires "Add-on for Linux Sysmon" ( https://splunkbase.splunk.com/app/6176/ )
This becomes even more complicated since some people might be confused by other add-ons in the Splunk store which are not supported anymore, but may be still found and downloaded from the store.

I think it would make this open source project more accessible if the prerequisites for running the attack data in a freshly installed instance of Splunk it would be specified.

Rewrite hostnames

The current code allows us to update timestamps to current time via update_timestamp: True. Could we also have a similar parameter to update the host before indexing in Splunk? Certain detections may rely on the host field or only trigger on activities happening on multiple hosts.

ID/UUID in Yaml files

Hi Folks,

We would like to integrate your ATT&CK data in CyCAT.org which is another open source project. But we have seen that a lot of yaml files don't include an ID/UUID? Do you plan to add one? It would help a lot to uniquely identify the rule.

Thanks a lot.

Cheers

Capture attacks being executed

Datasets are awesome and reading the description really makes me want to see what command was used and at what exact timestamp so I can analyze logs near/around it. Currently user is left to just the logs and hopefully they can find what happened and when.

It would be great to come up with some standardized way of tracking attack commands + timing. Obviously this initially might be restricted to only shell commands (GUI clicks are out of scope).

I'd propose looking to include any Ansible automated logs (do they show this?) for the Atomic Red things ... as well as linux typescript or bash_history with timestamping.

how do I make splunk es to check my uploaded logs

I have installed splunk es app and uploaded botsv1.stream_http.json
image
but incident_review and ess_security_posture is not hitting any event
image
how do I make splunk es to check my uploaded logs and generate a list of alerts like below. Please note that I am not checking the logs forwarded by agent, but the log files uploaded on the browser side
image
thank you

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.