Giter Site home page Giter Site logo

center-for-threat-informed-defense / cloud-analytics Goto Github PK

View Code? Open in Web Editor NEW
49.0 73.0 9.0 13.14 MB

Cloud Analytics helps defenders detect attacks to their cloud infrastructure by developing behavioral analytics for cloud platforms as well as a blueprint for how others can create and use cloud analytics effectively.

Home Page: https://ctid.mitre-engenuity.org/our-work/cloud-analytics/

License: Apache License 2.0

HCL 87.03% Shell 9.34% PowerShell 3.63%
cybersecurity ctid mitre-attack cyber-threat-intelligence analytics cloud cloud-computing cyber-analytics

cloud-analytics's Introduction

Cloud Analytics

This Cloud Analytics project researched and developed best practices to help defenders improve their ability to detect adversary behaviors in today's complex cloud environments. This repository contains behavioral analytics to detect attacks to cloud platforms and a blueprint for how others can create and use cloud analytics effectively.

Resources

Resource Description
Blueprint Document Best practices and lessons learned for developing cloud analytics.​
Analytics Analytics generated in Sigma format for the project.
CALDERA Emulation Tips Documentation on reproducing adversary emulation using Caldera.
Sigma Rule Information Documentation on using Sigma rules in relation to Cloud Analytics.
Support Resources Resources not part of final deliverable, but potentially useful.

Questions and Feedback

Please submit issues for any technical questions/concerns or contact [email protected] directly for more general inquiries.

Also see the guidance for contributors if are you interested in contributing or simply reporting issues.

Notice

Copyright 2022 MITRE Engenuity. Approved for public release. Document number CT0053

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

This project makes use of ATT&CK®

ATT&CK Terms of Use

cloud-analytics's People

Contributors

jonathanbaker avatar m3mike avatar markdavidson avatar markeaimark avatar mehaase avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

cloud-analytics's Issues

House keeping to prepare for publication

Taking inventory of this repository and noting down some final housekeeping before publication:

  • The screenshots in docs/Using Cloud Analytics with Caldera.md are broken links. (Looks like they are local paths on M3's machine?)
    • the contents of demo/docs/ seem to be duplicates of some items in docs/? Can we delete the former?
  • Remove unused files/folders:
    • .coveragerc
    • .github/workflows/
      -data/
  • Create a "Resources" block for README.md (see example below)

Resources

Resource Description
Attack Flow Specification An overview of the Attack Flow format and corresponding data dictionary.
Attack Flow JSON Schema The JSON of the Attack Flow schema.
Attack Flow JSON Example Document A JSON example of an Attack Flow.
Attack Flow Designer A GUI tool for building Attack Flows. (See "Getting Started" below)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.