Added new data sources

master
Marcus Bakker 2020-10-31 11:14:02 +01:00
parent cd5b71ea9f
commit b3705c782e
1 changed files with 85 additions and 1 deletions

View File

@ -4,7 +4,7 @@ version: 1.0
file_type: data-source-administration file_type: data-source-administration
name: empty-data-source-admin-file name: empty-data-source-admin-file
# Fill in the correct MITRE ATT&CK enterprise platform(s). Multiple can be included using a list # Fill in the correct MITRE ATT&CK enterprise platform(s). Multiple can be included using a list
# - (Windows, Linux, macOS, AWS, GCP, Azure, Azure AD, Office 365, SaaS) # - (Windows, Linux, macOS, PRE, AWS, GCP, Azure, Azure AD, Office 365, SaaS, Network)
# Also, take into account which data sources are applicable per platform. For more info see: # Also, take into account which data sources are applicable per platform. For more info see:
# - https://github.com/rabobank-cdc/DeTTECT/wiki/Data-sources-per-platform # - https://github.com/rabobank-cdc/DeTTECT/wiki/Data-sources-per-platform
platform: platform:
@ -35,6 +35,18 @@ data_sources:
timeliness: 0 timeliness: 0
consistency: 0 consistency: 0
retention: 0 retention: 0
- data_source_name: GCP audit logs
date_registered:
date_connected:
products: []
available_for_data_analytics: False
comment: ''
data_quality:
device_completeness: 0
data_field_completeness: 0
timeliness: 0
consistency: 0
retention: 0
- data_source_name: Process command-line parameters - data_source_name: Process command-line parameters
date_registered: date_registered:
date_connected: date_connected:
@ -119,6 +131,42 @@ data_sources:
timeliness: 0 timeliness: 0
consistency: 0 consistency: 0
retention: 0 retention: 0
- data_source_name: Network device command history
date_registered:
date_connected:
products: []
available_for_data_analytics: False
comment: ''
data_quality:
device_completeness: 0
data_field_completeness: 0
timeliness: 0
consistency: 0
retention: 0
- data_source_name: Network device configuration
date_registered:
date_connected:
products: []
available_for_data_analytics: False
comment: ''
data_quality:
device_completeness: 0
data_field_completeness: 0
timeliness: 0
consistency: 0
retention: 0
- data_source_name: Network device run-time memory
date_registered:
date_connected:
products: []
available_for_data_analytics: False
comment: ''
data_quality:
device_completeness: 0
data_field_completeness: 0
timeliness: 0
consistency: 0
retention: 0
- data_source_name: Windows event logs - data_source_name: Windows event logs
date_registered: date_registered:
date_connected: date_connected:
@ -203,6 +251,18 @@ data_sources:
timeliness: 0 timeliness: 0
consistency: 0 consistency: 0
retention: 0 retention: 0
- data_source_name: SSL/TLS certificates
date_registered:
date_connected:
products: []
available_for_data_analytics: False
comment: ''
data_quality:
device_completeness: 0
data_field_completeness: 0
timeliness: 0
consistency: 0
retention: 0
- data_source_name: SSL/TLS inspection - data_source_name: SSL/TLS inspection
date_registered: date_registered:
date_connected: date_connected:
@ -371,6 +431,18 @@ data_sources:
timeliness: 0 timeliness: 0
consistency: 0 consistency: 0
retention: 0 retention: 0
- data_source_name: Social media monitoring
date_registered:
date_connected:
products: []
available_for_data_analytics: False
comment: ''
data_quality:
device_completeness: 0
data_field_completeness: 0
timeliness: 0
consistency: 0
retention: 0
- data_source_name: Web logs - data_source_name: Web logs
date_registered: date_registered:
date_connected: date_connected:
@ -491,6 +563,18 @@ data_sources:
timeliness: 0 timeliness: 0
consistency: 0 consistency: 0
retention: 0 retention: 0
- data_source_name: Domain registration
date_registered:
date_connected:
products: []
available_for_data_analytics: False
comment: ''
data_quality:
device_completeness: 0
data_field_completeness: 0
timeliness: 0
consistency: 0
retention: 0
- data_source_name: Browser extensions - data_source_name: Browser extensions
date_registered: date_registered:
date_connected: date_connected: