OTRF / OSSEM-DM

OSSEM Detection Model
MIT License
167 stars 43 forks source link

User Entity might need to be broken down into Managed identity and service principal #35

Open Cyb3rWard0g opened 3 years ago

Cyb3rWard0g commented 3 years ago

For example a few sources of data in Azure track specific entities such as User, managed identities and service principals in separate logs:

https://github.com/mitre-attack/attack-datasources/blob/main/contribution/user_account.yml

Cyb3rWard0g commented 3 years ago

image