diff --git a/objects/elastic-detection-rule/definition.json b/objects/elastic-detection-rule/definition.json new file mode 100644 index 00000000..1008dc61 --- /dev/null +++ b/objects/elastic-detection-rule/definition.json @@ -0,0 +1,162 @@ +{ + "attributes": { + "author": { + "description": "Author(s) of the detection rule.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 1 + }, + "description": { + "description": "Human-readable description of what the rule detects.", + "misp-attribute": "text", + "ui-priority": 1 + }, + "false-positive": { + "description": "Known false positive scenario for the rule.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 2 + }, + "from": { + "description": "Look-back window the rule searches from on each run (e.g. now-6m).", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 2 + }, + "index": { + "description": "Index pattern(s) queried by the rule.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 1 + }, + "interval": { + "description": "Interval at which the rule is executed (e.g. 5m).", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 2 + }, + "language": { + "description": "Query language used by the rule.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1, + "values_list": [ + "kuery", + "lucene", + "eql", + "esql" + ] + }, + "license": { + "description": "License applied to the detection rule.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 0 + }, + "max-signals": { + "description": "Maximum number of alerts the rule can create per execution.", + "disable_correlation": true, + "misp-attribute": "counter", + "ui-priority": 0 + }, + "mitre-attack-tactic": { + "description": "MITRE ATT&CK tactic(s) associated with the rule.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 1 + }, + "mitre-attack-technique": { + "description": "MITRE ATT&CK technique(s) associated with the rule.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 1 + }, + "query": { + "description": "Query (KQL, Lucene, EQL, or ES|QL depending on language) implementing the detection.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 0 + }, + "reference": { + "description": "Reference URL for the rule source or documentation.", + "disable_correlation": true, + "misp-attribute": "link", + "multiple": true, + "ui-priority": 2 + }, + "risk-score": { + "description": "Risk score assigned to the rule (0-100).", + "disable_correlation": true, + "misp-attribute": "counter", + "ui-priority": 1 + }, + "rule-id": { + "description": "Unique identifier of the rule (the rule_id UUID field in Elastic).", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1 + }, + "rule-name": { + "description": "Human-readable name of the detection rule.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1 + }, + "severity": { + "description": "Severity assigned to the rule.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1, + "values_list": [ + "low", + "medium", + "high", + "critical" + ] + }, + "tag": { + "description": "Free-text tag associated with the rule.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 2 + }, + "type": { + "description": "Elastic detection rule type.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1, + "values_list": [ + "query", + "eql", + "esql", + "threshold", + "machine_learning", + "threat_match", + "new_terms", + "saved_query" + ] + }, + "version": { + "description": "Version of the detection rule.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 0 + } + }, + "description": "An object describing an Elastic Security detection rule (KQL/Lucene/EQL/ES|QL query), its scheduling, risk scoring, and MITRE ATT&CK mapping, following the Elastic detection-rules schema.", + "meta-category": "misc", + "name": "elastic-detection-rule", + "requiredOneOf": [ + "query", + "rule-id", + "rule-name" + ], + "uuid": "5867f36d-b252-4cc6-b939-34e125274547", + "version": 1 +} \ No newline at end of file diff --git a/objects/kql-analytics-rule/definition.json b/objects/kql-analytics-rule/definition.json new file mode 100644 index 00000000..4ff1dd10 --- /dev/null +++ b/objects/kql-analytics-rule/definition.json @@ -0,0 +1,151 @@ +{ + "attributes": { + "comment": { + "description": "A description of what the analytics rule detects.", + "misp-attribute": "comment", + "ui-priority": 0 + }, + "data-connector": { + "description": "Required data connector(s) or table(s) the query depends on.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 2 + }, + "entity-field": { + "description": "Query result field mapped to an entity, paired with entity-type.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 3 + }, + "entity-type": { + "description": "Entity type mapped from the query results (e.g. Account, Host, IP).", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 3 + }, + "kind": { + "description": "Analytics rule kind.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1, + "values_list": [ + "Scheduled", + "NRT", + "MicrosoftSecurityIncidentCreation", + "Fusion", + "MLBehaviorAnalytics", + "ThreatIntelligence" + ] + }, + "mitre-attack-tactic": { + "description": "MITRE ATT&CK tactic(s) associated with the rule.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 1 + }, + "mitre-attack-technique": { + "description": "MITRE ATT&CK technique(s) associated with the rule.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 1 + }, + "product": { + "description": "Microsoft product the KQL analytics rule is deployed on.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1, + "values_list": [ + "Microsoft Sentinel", + "Microsoft Defender XDR" + ] + }, + "query": { + "description": "KQL (Kusto Query Language) query implementing the detection.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 0 + }, + "query-frequency": { + "description": "How often the query runs (ISO 8601 duration, e.g. PT1H).", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 2 + }, + "query-period": { + "description": "Look-back period searched by the query (ISO 8601 duration, e.g. PT1H).", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 2 + }, + "reference": { + "description": "Reference URL for the rule source or documentation.", + "disable_correlation": true, + "misp-attribute": "link", + "multiple": true, + "ui-priority": 2 + }, + "rule-id": { + "description": "Unique identifier (GUID) of the analytics rule.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1 + }, + "rule-name": { + "description": "Human-readable name of the analytics rule.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1 + }, + "severity": { + "description": "Severity assigned to the rule.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1, + "values_list": [ + "Informational", + "Low", + "Medium", + "High" + ] + }, + "trigger-operator": { + "description": "Operator used to compare the result count against trigger-threshold.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 2, + "values_list": [ + "gt", + "lt", + "eq", + "ne" + ] + }, + "trigger-threshold": { + "description": "Result count threshold that triggers an alert.", + "disable_correlation": true, + "misp-attribute": "counter", + "ui-priority": 2 + }, + "version": { + "description": "Version of the analytics rule.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 0 + } + }, + "description": "An object describing a Microsoft Sentinel or Microsoft Defender XDR KQL analytics rule (Scheduled/NRT), including scheduling, alert thresholds, entity mappings, and MITRE ATT&CK mapping.", + "meta-category": "misc", + "name": "kql-analytics-rule", + "requiredOneOf": [ + "query", + "rule-id", + "rule-name" + ], + "uuid": "f23e6424-ce43-410d-a3b3-7c15e79cf1ac", + "version": 1 +} \ No newline at end of file diff --git a/objects/splunk-rule/definition.json b/objects/splunk-rule/definition.json new file mode 100644 index 00000000..7934e13d --- /dev/null +++ b/objects/splunk-rule/definition.json @@ -0,0 +1,128 @@ +{ + "attributes": { + "analytic-story": { + "description": "Splunk Security Content analytic story / use case grouping this detection belongs to.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 2 + }, + "app": { + "description": "Splunk app or add-on namespace the search runs in (e.g. Splunk Enterprise Security, ES Content Update).", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1 + }, + "author": { + "description": "Author(s) of the detection search.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 1 + }, + "comment": { + "description": "A description of the Splunk detection/correlation search.", + "misp-attribute": "comment", + "ui-priority": 0 + }, + "data-source": { + "description": "Sourcetype(s), index(es), or data model(s) queried by the search.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 1 + }, + "known-false-positives": { + "description": "Known false positives or limitations of the detection.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 2 + }, + "mitre-attack-id": { + "description": "MITRE ATT&CK technique ID(s) associated with the detection.", + "disable_correlation": true, + "misp-attribute": "text", + "multiple": true, + "ui-priority": 1 + }, + "reference": { + "description": "Reference URL for the detection source or documentation.", + "disable_correlation": true, + "misp-attribute": "link", + "multiple": true, + "ui-priority": 2 + }, + "risk-score": { + "description": "Risk score assigned to the detection (0-100).", + "disable_correlation": true, + "misp-attribute": "counter", + "ui-priority": 1 + }, + "rule-id": { + "description": "Unique identifier of the detection, such as the Splunk Security Content id field.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1 + }, + "rule-name": { + "description": "Human-readable name of the Splunk detection/correlation search.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1 + }, + "schedule": { + "description": "Search schedule or cron_schedule the detection runs on.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 2 + }, + "severity": { + "description": "Severity assigned to the detection.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1, + "values_list": [ + "informational", + "low", + "medium", + "high", + "critical" + ] + }, + "spl": { + "description": "Search Processing Language (SPL) query implementing the detection.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 0 + }, + "type": { + "description": "Splunk Security Content detection type.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 1, + "values_list": [ + "TTP", + "Hunting", + "Anomaly", + "Correlation", + "Baseline" + ] + }, + "version": { + "description": "Version of the detection search.", + "disable_correlation": true, + "misp-attribute": "text", + "ui-priority": 0 + } + }, + "description": "An object describing a Splunk detection/correlation search (SPL query), its scheduling, risk scoring, and MITRE ATT&CK mapping, following the Splunk Security Content (ESCU) detection format.", + "meta-category": "misc", + "name": "splunk-rule", + "requiredOneOf": [ + "spl", + "rule-id", + "rule-name" + ], + "uuid": "13071b9d-d35b-465c-8e35-f47bc0d29f09", + "version": 1 +} \ No newline at end of file