Open Source Security Event Metadata ! Data engineers! #ThreatHunting @OTR_Communitygithub.com/OTRF/OSSEM https://ossemproject.com/introJoined September 2019
🚀 Any NEW fields on the schemas for #SysmonForLinux events compared to Windows🤔?
@Cyb3rPandaH used our #Sysmon for Windows & Linux data dictionaries in a python 🐍 script to answer that😎
✅ ParentUser (ProcessCreate)
✅ User (EID 5,9,11)
🖇️ Script: github.com/OTRF/OSSEM-DD/…
Today, Microsoft is open sourcing Cloud Katana, a cloud-native serverless application built on the top of Azure Functions to assess security controls in the cloud and hybrid cloud environments. Read about the design principles and learn how to deploy: msft.it/6011n46MT
It has launched! ATT&CK v9 is now live with refactored data sources, ATT&CK for Containers, Google Workspace as a platform and more! Read about new data sources and the rest of the update at medium.com/mitre-attack/a… or attack.mitre.org/resources/upda… for new/changed groups/techniques/sw.
💥😱 @tiraniddo added "named pipe RPC client transport" to NtObjectManager 🔥 Thank you very much James for all your work 👏!
I'll create PS scripts to cover a few scenarios 🍻 (Img 4)
If anyone would like to help me, let me know 😉 @OTR_Communitygithub.com/Cyb3rWard0g/Wi…
🚨 New version of our "attackcti" Python 🐍 library to query @MITREattack in STIX format via their public TAXII server has been released!
1⃣ ICS ATT&CK Integration ✅
2⃣ Basic Notebook to explore ICS Content ✅
📔 Binder: mybinder.org/v2/gh/OTRF/ATT…
📦Repo: github.com/OTRF/ATTACK-Py…
In their #THIRSummit talk, @Cyb3rPandaH & @jamieantisocial illustrates how we can avoid the typical cat and mouse games by modeling the data sources defined in ATT&CK to recognize, track, and even predict the malicious scent of adversaries.
Watch it now: youtu.be/eKeydMrXsOE
Thank you @jaredhaight 😊🙏 With the latest updates to @MITREattack data sources by @Cyb3rPandaH , we are translating that doc to YAML files to create additional documentation and hopefully get contributions from the InfoSec Community 😊
github.com/OTRF/OSSEM-DM/…
Formalizing the mapping of security events to the @MITREattack data source objects concepts 🍻 We would love to hear your feedback and see your contributions to this community-led effort!! 💜 Thank you @Cyb3rPandaH 💜
Blog: medium.com/threat-hunters…
🙏So happy to see our initial data modeling concepts applied to enhance @MITREattack . This is a more practical & less subjective approach to map event logs ➡️ att&ck data sources. We hope this helps the community to improve their data collection strategy. Thanks @Cyb3rPandaH 🍻
55K Followers 3K FollowingDirector of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
5 Followers 98 FollowingData AI Engineer | Mastering pipelines to turn raw data into AI breakthroughs | Builder sharing code, tools, & real-world hacks | Learning & growing together.
17 Followers 117 FollowingHusband, Father, Passionate about all things Digital, Cloud and Cyber Security, Vynil Lover, Vynil Collector, and of course Linux User & VMware User !!
1K Followers 3K Following#ThreatIntel Researcher @S2W_Official @TALON_INTEL
Main Author of Threat Intel Report 'Campaign DOKKAEBI : Documents of Korean and Evil Binary' / Formerly FSI
2K Followers 5 FollowingContributing datasets, from different platforms, to the InfoSec community to expedite data analysis and threat research! https://t.co/j62Xx21lEc
6K Followers 7 FollowingI document #ThreatHunting playbooks in the form of #jupyter notebooks and share them with the world! https://t.co/djKSwSGXgA @Cyb3rWard0g