opencybersecurityalliance / PACE

Posture Attribute Collection and Evaluation
Other
23 stars 4 forks source link

PSD: Add Kestrel Outputs to Security Attributes #63

Open sparrell opened 1 year ago

sparrell commented 1 year ago

Kestrel does threat hunting and produces outputs about threats (or lack thereof) in the system. These outputs should be inputs into PACE either directly (as STIX observables produced by Kestrel) or indirectly (if Kestrel was part of CACAO playbook, another playbook step might be updating PACE)