unfetter-discover / unfetter

The main project for the Unfetter-Discover application. This is the project that will hold the configuration files, the docker-compose files, issue tracking, and documentation
Other
406 stars 78 forks source link

Improve Sensor Complexity #322

Open infosec-alchemist opened 7 years ago

infosec-alchemist commented 7 years ago

Map sensors to the STIX Cyber Observable data types that the sensor COULD collect. Use the assessments workflow to allow support for identifying that the sensor DOES collect.

In cases like SYSMON, there is a large amount of data that SYSMON is capable of collecting. however, most deployments reduce those to reduce data collection. The Assessments workflow should recognize the delta between what is being collected in a particular environment, and what is possible.

Support hard coded data entry for now.

Consider adding the following sensor properties:

j987987 commented 5 years ago

Removing this from the milestone as it's not in the scope of the sprint.