Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Rule Tuning] Update rules with ATT&CK tactic and technique metadata #272

Closed
threat-punter opened this issue Sep 8, 2020 · 2 comments
Closed
Assignees
Labels
Rule: Tuning tweaking or tuning an existing rule

Comments

@threat-punter
Copy link
Contributor

threat-punter commented Sep 8, 2020

Description

Currently, we cannot include an ATT&CK tactic in a rule without a technique. Some of our rules have no ATT&CK tactic/technique metadata in them. E.g. Some Okta rules that were part of the 7.9 release.

Once elastic/kibana#69166 is resolved, we should update our existing rules to include the relevant ATT&CK tactic metadata (and the technique metadata if there is an appropriate technique to map the rule to at that time).

We've submitted some information on new techniques to ATT&CK to help close some gaps, but they're still reviewing that information.

@threat-punter threat-punter added the Rule: Tuning tweaking or tuning an existing rule label Sep 8, 2020
@threat-punter threat-punter self-assigned this Sep 8, 2020
@rw-access
Copy link
Contributor

Potentially a duplicate of #51 and/or #52

@threat-punter
Copy link
Contributor Author

You're right. I missed that. Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Rule: Tuning tweaking or tuning an existing rule
Projects
None yet
Development

No branches or pull requests

2 participants