Bro/Zeek ATT&CK-based Analytics and Reporting (BZAR), by MITRE

"Fernandez, Mark I" <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <DM2PR09MB07788CFC16E74AFA3C32A53BCF580@DM2PR09MB0778.namprd09.prod.outlook.com>
All,

 

MITRE has created a set of Bro/Zeek scripts to detect ATT&CK-like
adversarial activity.  The project is called BZAR - Bro/Zeek ATT&CK-based
Analytics and Reporting.

 

MITRE ATT&CK is a publicly-available, curated knowledge base for cyber
adversary behavior, reflecting the various phases of the adversary lifecycle
and the platforms they are known to target. The ATT&CK model includes
behaviors of numerous threats groups.

 

BZAR is a set of Bro/Zeek scripts utilizing the SMB and DCE-RPC protocol
analyzers and the File Extraction Framework to detect ATT&CK-like activity,
correlate certain techniques, and write to the Notice Log.

 

BZAR is publicly released as open source, under MITRE case number 18-2489.
It is available for download at the following URL:

*	https://github.com/mitre-attack/car/tree/master/implementations/bzar

 

For more information on MITRE ATT&CK, visit https://attack.mitre.org.

 

 

Mark I. Fernandez

The MITRE Corporation

 <mailto:[email protected]> [email protected]

 

P.S.  It does not yet support the Bro/Zeek Package Manager (this is on the
todo list).

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
smime.p7s (application/pkcs7-signature, 4.9 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.