center-for-threat-informed-defense / attack-flow

Attack Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by developing a representation of attack flows, modeling attack flows for a small corpus of incidents, and creating visualization tools to display attack flows.
https://ctid.io/attack-flow
Apache License 2.0
527 stars 84 forks source link

Add Scenario of " SolarWinds Breach" #44

Closed alaanasser00 closed 1 year ago

alaanasser00 commented 2 years ago

Information extracted from: https://www.picussecurity.com/resource/blog/ttps-used-in-the-solarwinds-breach

codecov[bot] commented 2 years ago

Codecov Report

Merging #44 (60d0384) into main (93a39a2) will not change coverage. The diff coverage is n/a.

@@           Coverage Diff           @@
##             main      #44   +/-   ##
=======================================
  Coverage   97.39%   97.39%           
=======================================
  Files           5        5           
  Lines         269      269           
=======================================
  Hits          262      262           
  Misses          7        7           

Continue to review full report at Codecov.

Legend - Click here to learn more Δ = absolute <relative> (impact), ø = not affected, ? = missing data Powered by Codecov. Last update 93a39a2...60d0384. Read the comment docs.

sonarcloud[bot] commented 2 years ago

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

alaanasser00 commented 2 years ago

Thank you @sanchezmia for your time to write this detailed response. I'll make sure to add these changes.

mehaase commented 1 year ago

Hi @alaanasser00, we have some interest in completing the SolarWinds flow -- are you okay if we update this flow on your behalf? We would still list you as a co-author.

alaanasser00 commented 1 year ago

Hi @mehaase, sure! I wanted to complete it but unfortunately I don't have enough time to focus on it. Nevertheless, hit me up if you need any help. Have a great weekend.

mehaase commented 1 year ago

The SolarWinds flow has been upgraded to Attack Flow v2 and included in today's public release. Thank you @alaanasser00 and @sanchezmia!