MITRE Framework

This entry is part 12 of 17 in the series Threat Detection Engineering

Views: 19MITRE ATT&CK Navigator MITRE D3FEND MITRE ENGAGE MITRE Engage MITRE Engage Matrix ATT&CK Emulation Plans Center of Threat-Informed Defense (CTID) Cyber Analytics Repository

ELASTIC SIEM: Kibana Query Language (KQL) 

This entry is part 13 of 17 in the series Threat Detection Engineering

Views: 27Different Syntax Languages Kibana supports two types of syntax languages for querying in Kibana: KQL (Kibana Query Language) and Lucene Query Syntax. Special Characters Certain characters are reserved in ELK queries and must be escaped before usage. Reserved characters in ELK include +, -, =, &&, ||, &, | and !. For instance, using the + character in a query will result in an error; to escape this character, precede it with … Read more

SOC Tools and Useful Links

This entry is part 13 of 17 in the series Threat Detection Engineering

Views: 191- IP & URL Reputation 1. Virus Total : URL Scan : AbuseIPDB: Cisco Talos: IBM X-Force: URL Filtering(Palo Alto): URL Filtering(Symantec): IP Void: URL Void: 2- File | Hash | Search | Analysis | Sandboxing 1. File Extension >> 2. LOLBAS >> 3. GTFOBins >> 4. File Hash Check >> 5. Hash Search … Read more