Skip to content

Use Cases - Basics #12

Description

@styx0x6
  • Add / Delete / Modify Detection Use Cases:
    • Including data from local and a provider (that will come later with connectors)
    • New ideas.
      • Mapping ideas with implemented Use Cases when they appear from connector:
        • if 'not_implemented' status => Just a new DUC in the catalog.
        • if 'requested' or else to check => Should map a DEF the first time.
    • Fields from vendor versus added-value fields.
    • Added-value fields:
      • Use Cases scoring:
        • Basic Scoring System
      • Documentation as full rich text (What to detect, How to implement, How to test, Whitelists, etc.)
      • Ability to attach external documentation to Use Cases, or to set an external reference
      • Mapping and documentation of source logs (required events, required source)
      • Basic development planning & follow-up (in use case).
      • DUC related playbook for security analyst
        • Detection rule documentation: queries and threshold that permit to trigger the DUC
        • Runbook: analysis documentation used to launch a deeper analysis, queries, etc. to more understand the related context and launch the IR.
    • Ability to store external general documentation, or to set an external reference
    • Basic development planning & follow-up as a general overview (like Open Points tasks list)
    • Search and filtering out in Detection Use Cases list

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions