Re: Bro/Zeek ATT&CK-based Analytics and Reporting (BZAR), by MITRE
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CAM1mTCpOfgPBJdtmGJBTtX19f3ppE2HC8-meH-0N2TboUR4J6Q@mail.gmail.com> |
Nice work, thanks for sharing! - Jon Zeolla [email protected] On Wed, Mar 27, 2019 at 9:09 AM Fernandez, Mark I <[email protected]> wrote: > All, > > > > MITRE has created a set of Bro/Zeek scripts to detect ATT&CK-like > adversarial activity. The project is called BZAR – Bro/Zeek ATT&CK-based > Analytics and Reporting. > > > > MITRE ATT&CK is a publicly-available, curated knowledge base for cyber > adversary behavior, reflecting the various phases of the adversary > lifecycle and the platforms they are known to target. The ATT&CK model > includes behaviors of numerous threats groups. > > > > BZAR is a set of Bro/Zeek scripts utilizing the SMB and DCE-RPC protocol > analyzers and the File Extraction Framework to detect ATT&CK-like activity, > correlate certain techniques, and write to the Notice Log. > > > > BZAR is publicly released as open source, under MITRE case number > 18-2489. It is available for download at the following URL: > > - https://github.com/mitre-attack/car/tree/master/implementations/bzar > > > > For more information on MITRE ATT&CK, visit https://attack.mitre.org. > > > > > > *Mark I. Fernandez* > > The MITRE Corporation > > [email protected] > > > > P.S. It does not yet support the Bro/Zeek Package Manager (this is on the > todo list). > _______________________________________________ > Zeek mailing list > [email protected] > http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek