Skip to content

Commit

Permalink
add PR and update dates
Browse files Browse the repository at this point in the history
  • Loading branch information
ebeahan committed Jul 6, 2021
1 parent 5414b2f commit 25eb02c
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 2 deletions.
3 changes: 2 additions & 1 deletion rfcs/text/0008-threat-intel.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
<!-- Leave this ID at 0000. The ECS team will assign a unique, contiguous RFC number upon merging the initial stage of this RFC. -->

- Stage: **2 (candidate)** <!-- Update to reflect target stage. See https://elastic.github.io/ecs/stages.html -->
- Date: **2021-06-23** <!-- The ECS team sets this date at merge time. This is the date of the latest stage advancement. -->
- Date: **2021-07-06** <!-- The ECS team sets this date at merge time. This is the date of the latest stage advancement. -->

Elastic Security Solution will be adding the capability to ingest, process and utilize threat intelligence information for increasing detection coverage and helping analysts make quicker investigation decisions. Threat intelligence can be collected from a number of sources with a variety of structured and semi-structured data representations. This makes threat intelligence an ideal candidate for ECS mappings. Threat intelligence data will require ECS mappings to normalize it and make it usable in our security solution. This RFC is focused on identifying new field sets and values that need to be created for threat intelligence data. Existing ECS field reuse will be prioritized where possible. If new fields are required we will utilize [STIX Cyber Observable data model](https://docs.oasis-open.org/cti/stix/v2.1/cs01/stix-v2.1-cs01.html#_mlbmudhl16lr) as guidance.

Expand Down Expand Up @@ -359,6 +359,7 @@ Some examples of commercial intelligence include:
* Stage 1 correction: https://github.com/elastic/ecs/pull/1100
* Stage 1 (originally stage 2 prior to removal of RFC stage 4): https://github.com/elastic/ecs/pull/1127
* Stage 2: https://github.com/elastic/ecs/pull/1293
* Stage 2 addendum: https://github.com/elastic/ecs/pull/1502


<!--
Expand Down
3 changes: 2 additions & 1 deletion rfcs/text/0021-threat-enrichment.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# 0021: Threat Enrichment

- Stage: **2 (candidate)** <!-- Update to reflect target stage. See https://elastic.github.io/ecs/stages.html -->
- Date: **2021-06-24** <!-- The ECS team sets this date at merge time. This is the date of the latest stage advancement. -->
- Date: **2021-07-06** <!-- The ECS team sets this date at merge time. This is the date of the latest stage advancement. -->

<!--
Stage 0: Provide a high level summary of the premise of these changes. Briefly describe the nature, purpose, and impact of the changes. ~2-5 sentences.
Expand Down Expand Up @@ -234,6 +234,7 @@ e.g.:
* Stage 0: https://github.com/elastic/ecs/pull/1386
* Stage 1: https://github.com/elastic/ecs/pull/1400
* Stage 2: https://github.com/elastic/ecs/pull/1460
* Stage 2 addendum: https://github.com/elastic/ecs/pull/1502

<!--
* Stage 1: https://github.com/elastic/ecs/pull/NNN
Expand Down

0 comments on commit 25eb02c

Please sign in to comment.