Skip to content

Instantly share code, notes, and snippets.

@it-sec-std
Last active January 25, 2018 02:25
Show Gist options
  • Save it-sec-std/0e6fa51cd7746be208ffb7757cf6966e to your computer and use it in GitHub Desktop.
Save it-sec-std/0e6fa51cd7746be208ffb7757cf6966e to your computer and use it in GitHub Desktop.
Solutions

Event processing solutions

Unfetter

Проект Unfetter - open source, который автоматизирует применение ATT&CK и CAR в вашей сети

Unfetter is a community-driven suite of open source tools leveraging the MITRE ATT&CK™ framework, shifting the focus from indicators to a behavior-based methodology. This allows you to more effectively assess your risk, advance your security posture, and implement mitigations in a systemic, measurable, and meaningful way.

Official page: https://iadgov.github.io/unfetter/ Reps:

Unfetter architecture

References:

MITRE’s Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK™) is a curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target. ATT&CK is useful for understanding security risk against known adversary behavior, for planning security improvements, and verifying defenses work as expected.

The Cyber Analytics Repository (CAR) is a knowledge base of analytics developed by MITRE based on the Adversary Tactics, Techniques, and Common Knowledge (ATT&CK™) adversary model.

If you want to start exploring try viewing a list of all analytics or use the CAR Exploration Tool (CARET).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment