OSSEM-DM icon indicating copy to clipboard operation
OSSEM-DM copied to clipboard

OSSEM Detection Model

Results 16 OSSEM-DM issues
Sort by recently updated
recently updated
newest added

Added a missing '-' character to a .yml file. Added a missing ' ' character to a .yml file. Problem came from attempting to parse the .yml using any common...

Support for current year

PR Comment: #46 @H1L021 What are your thoughts on adding event 4611 to the data source / component: Logon Session / Logon Session Metadata? I understand this event is not...

https://github.com/OTRF/OSSEM-DD/blob/main/windows/etw-providers/Microsoft-Windows-RPC/events/event-5_v1.yml https://github.com/OTRF/OSSEM-DD/blob/main/windows/etw-providers/Microsoft-Windows-RPC/events/event-6_v1.yml

enhancement
feature
structure

For example a few sources of data in Azure track specific entities such as User, managed identities and service principals in separate logs: https://github.com/mitre-attack/attack-datasources/blob/main/contribution/user_account.yml

enhancement

- create excel template for event relationship, i will share mine from the azure work. - update python script excel/md to yaml in DD to be compatible with new excel...

feature
infrastructure

#24 : user attempted to authenticate to computer: We will get back to you about the "computer" data element. We need to review this concept and define which term would...

documentation
hot fix

We need help with the mapping of security events to ATT&CK Volume data source. Potential security events providers: - Windows Security Events - OSQuery - AWS - Azure - GCP...

research
feature