opensearch-project / security-analytics

Security Analytics enables users for detecting security threats on their security event log data. It will also allow them to modify/tailor the pre-packaged solution.
Apache License 2.0
64 stars 69 forks source link

Ioc match model #1038

Closed eirsep closed 1 month ago

eirsep commented 1 month ago

Description

An Ioc Match is an entity that is created as part of malicious Ioc Scanning Ioc match maps an IoC to a list of documents that contain the ioc

Ioc match primarily contains the following information:

It's in essence the reverse mapping of a finding that maps a document to a list of malicious IoCs found

Issues Resolved

[List any issues this PR will resolve]

Check List

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license. For more information on following Developer Certificate of Origin and signing off your commits, please check here.