Re: Bro/Zeek ATT&CK-based Analytics and Reporting (BZAR), by MITRE

"[email protected]" <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CAM1mTCpOfgPBJdtmGJBTtX19f3ppE2HC8-meH-0N2TboUR4J6Q@mail.gmail.com>
Nice work, thanks for sharing!

- Jon Zeolla
[email protected]


On Wed, Mar 27, 2019 at 9:09 AM Fernandez, Mark I <[email protected]>
wrote:

> All,
>
>
>
> MITRE has created a set of Bro/Zeek scripts to detect ATT&CK-like
> adversarial activity.  The project is called BZAR – Bro/Zeek ATT&CK-based
> Analytics and Reporting.
>
>
>
> MITRE ATT&CK is a publicly-available, curated knowledge base for cyber
> adversary behavior, reflecting the various phases of the adversary
> lifecycle and the platforms they are known to target. The ATT&CK model
> includes behaviors of numerous threats groups.
>
>
>
> BZAR is a set of Bro/Zeek scripts utilizing the SMB and DCE-RPC protocol
> analyzers and the File Extraction Framework to detect ATT&CK-like activity,
> correlate certain techniques, and write to the Notice Log.
>
>
>
> BZAR is publicly released as open source, under MITRE case number
> 18-2489.  It is available for download at the following URL:
>
>    - https://github.com/mitre-attack/car/tree/master/implementations/bzar
>
>
>
> For more information on MITRE ATT&CK, visit https://attack.mitre.org.
>
>
>
>
>
> *Mark I. Fernandez*
>
> The MITRE Corporation
>
> [email protected]
>
>
>
> P.S.  It does not yet support the Bro/Zeek Package Manager (this is on the
> todo list).
> _______________________________________________
> Zeek mailing list
> [email protected]
> http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.