google / dfiq

DFIQ is a collection of investigative questions and the approaches for answering them
http://dfiq.org/
Apache License 2.0
262 stars 21 forks source link

Support Analysis Suggestions in Approaches #4

Open lo-chr opened 1 year ago

lo-chr commented 1 year ago

Expected Behavior

The project should support the description of "analysis suggestions" in the approach definition file. I would propose a new subsection suggestion under the view section.

There are cases, where typical (malicious) activity has similarities from one threat actor to another. It would be helpful to integrate such hints, so that analysts can get an idea what to look for.

Actual Behavior

Feature not included.

Steps to Reproduce the Problem

not applicable

Specifications

obsidianforensics commented 1 year ago

Hi there, thanks for the suggestion. I've published the Markdown version of the DFIQ specification: https://dfiq.org/contributing/specification/

I see a few places where an analysis suggestion could fit:

Could you take a look and let me know if either fits what you intended with suggestion?

I've put some similar "suggestion"-type bits in some Facets (like the example in the Spec) that inform the analyst what to look for. This was my attempt at an informal "modifier" for the Questions - rather than have different questions for looking for a lot of file downloads at once, or look for only one file download, or even for periodic file downloads, to just have one "file downloaded" question, and then the analyst modify their analysis to fit the Facet.

lo-chr commented 1 year ago

Hey, thanks for the effort and the updated documentation! Unfortunately, I'm not sure, if one of the suggested fields really solves the issue:

Hope this makes sense. :-)