Giter Site home page Giter Site logo

oasis-tcs / openc2-ap-hunt Goto Github PK

View Code? Open in Web Editor NEW
4.0 8.0 3.0 639 KB

OASIS OpenC2 TC: Developing an Actuator Profile to manage threat hunting activities. The AP will define the Actions, Targets, Specifiers and Options to manage Threat Hunting consistent with the OpenC2 Language Specification. https://github.com/oasis-tcs/openc2-ap-hunt

Home Page: https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=openc2

License: Other

openc2-ap-hunt's Introduction

README

Work Product ReadMe Logo

oasis-avatar An OASIS Work Product Repository oasis-avatar

Members of the OASIS Open Command and Control (OpenC2) Technical Committee use this GitHub repository as part of the TC's chartered work. Contributors must be Members of the TC. Work is governed by the OASIS policies and is not done under typical open source licensing. For more details, see the Contributions and Licensing sections below.

๐Ÿ“˜ OpenC2 Actuator Profile for Threat Hunting ๐Ÿ“˜

This repository support development of a specification defining an actuator profile (AP) to automate management of cyber threat hunting activities using OpenC2.

๐Ÿ”€ Repository Organization ๐Ÿ”€

branches

OpenC2 work product repositories are organized a bit differently than typical open source software project repositories:

  • The Published (default) branch represents the current, stable, approved version of the work product. If the product hasn't progressed past an OASIS Committee Specification Draft (CSD), this branch is essentially empty.
  • The Working branch is where all work-in-progress content is captured, and is the place to go for the current working version of this work product.

More information about the TC's repository organizing conventions and branching strategy can be found in our Documentation Norms.

๐Ÿ—จ๏ธ Description ๐Ÿ—จ๏ธ

This specification defines an actuator profile to automate management of cyber threat hunting activities using OpenC2. Threat hunting is the process of proactively and iteratively searching through networks and on endpoints to detect and isolate cyber observables that may indicate threats that evade existing security solutions. This actuator profile defines the OpenC2 Actions, Targets, Arguments, and Specifiers along with conformance clauses to enable the operation of OpenC2 Producers and Consumers in the context of cyber threat hunting. It covers invocation of stored hunting processes (e.g., โ€œhunt booksโ€), passing of hunt parameters, selection of analytics to apply to hunt data, and the expected type(s) and format(s) of information returned by hunting processes.

โœ๏ธ Contributions โœ๏ธ

As stated in this repository's CONTRIBUTING file, contributors to this repository are expected to be Members of the OASIS OpenC2 TC, for any substantive change requests. Anyone wishing to contribute to this GitHub project and participate in the TC's technical activity is invited to join as an OASIS TC Member. Public feedback is also accepted, subject to the terms of the OASIS Feedback License.

๐Ÿ“œ Licensing ๐Ÿ“œ

Please see the LICENSE file for description of the license terms and OASIS policies applicable to the TC's work in this GitHub project. Content in this repository is intended to be part of the OpenC2 TC's permanent record of activity, visible and freely available for all to use, subject to applicable OASIS policies, as presented in the repository LICENSE file.

๐Ÿ—จ๏ธ Further Description of this Repository ๐Ÿ—จ๏ธ

This repository is designed to support TC members' work on a formal specification that describes the OpenC2 Actuator Profile for Threat Hunting. This GitHub repository supports development of the content and change tracking for the OpenC2 Actuator Profile for Threat Hunting as new working draft level revisions are created and the associated CSDs mature.

Members of the OASIS Open Command and Control (OpenC2) TC create and manage technical content in this TC GitHub repository ( https://github.com/oasis-tcs/openc2-ap-hunt ) as part of the TC's chartered work (i.e., the program of work and deliverables described in its charter).

OASIS TC GitHub repositories, as described in GitHub Repositories for OASIS TC Members' Chartered Work, are governed by the OASIS TC Process, IPR Policy, and other policies, similar to TC Wikis, TC JIRA issues tracking instances, TC SVN/Subversion repositories, etc. While they make use of public GitHub repositories, these TC GitHub repositories are distinct from OASIS Open Repositories, which are used for development of open source licensed content.

๐Ÿ“ฉ Contact ๐Ÿ“ฉ

Please send questions or comments about OASIS TC GitHub repositories to the OASIS TC Administrator. For questions about content in this repository, please contact the TC Chair or Co-Chairs as listed on the the OpenC2 TC's OASIS home page.

openc2-ap-hunt's People

Contributors

dlemire60 avatar oasis-op-admin avatar

Stargazers

 avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.