Skip to content

[Defend] Map Elastic Defend events directly to MITRE ATT&CK #82

@nicpenning

Description

@nicpenning

Today many EDRs will tag or map an event to MITRE when possible, not just alerts. A basic example of such mapping can be found here (https://github.com/olafhartong/sysmon-modular/blob/master/1_process_creation/include_bitsadmin.xml, https://github.com/olafhartong/sysmon-modular?tab=readme-ov-file#mitre-attack) at a community Sysmon repository where it does this very well. Elastic does not do this with the events and I think it should. An alert for every mitre technique doesn't make much sense, it should live at the event level of possible.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions