Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add ATT&CK subtechniques #52

Closed
rw-access opened this issue Jul 13, 2020 · 1 comment
Closed

Add ATT&CK subtechniques #52

rw-access opened this issue Jul 13, 2020 · 1 comment
Labels
enhancement New feature or request v7.10.0

Comments

@rw-access
Copy link
Contributor

rw-access commented Jul 13, 2020

ATT&CK subtechniques are official.

We should update our rules to use them, and figure out the optimal schema for ECS and the detection engine. We also need to improve our rule.threat mappings and use the latest information in ATT&CK since some techniques became subtechniques and others split. ATT&CK has subtechniques-crosswalk.json to track these changes

There's an ECS issue here:
elastic/ecs#867

When we have a good structure in mind for the schema, create an issue for Kibana to add support to the detection engine. We can start with the API first and they can add UI support after.

@rw-access
Copy link
Contributor Author

Duplicate of #215

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request v7.10.0
Projects
None yet
Development

No branches or pull requests

1 participant