Re: : Bro/Zeek ATT&CK-based Analytics and Reporting (BZAR), by MITRE

Patrick Kelley <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CA+WAcdT06sKGrL_S-f01EO_YEYNiPmcxJ3M2sfeNoyhuNu6qPg@mail.gmail.com>
We'll try to crack something out around PTH, if nothing exists already.
We'll post it here when done.

We have the pcaps from the lab and live engagements. Should be able to
knock that out.

On Thu, Mar 28, 2019 at 9:35 AM Fernandez, Mark I <[email protected]>
wrote:

> Alex,
>
>
>
> >> - Is the repository going to be maintain and updated
>
> >> e.g new attacks and categories techniques ?
>
>
>
> To be determined.  We may do some small updates in the near future.
> Contributions from the Zeek community are welcome, and I believe we’ll be
> able to incorporate community contributions.
>
>
>
> >>- Second isn't possible to detect pth attack throught
>
> >> *bzar_smb.bro ?*
>
>
>
> Pass-the-Hash (pth) was not in the initial scope of the BZAR work.  I
> think it would be great to add it, but I haven’t done a market survey to
> see if anyone else has already developed pth detection for Zeek.
>
>
>
> Cheers,
>
> Mark
> _______________________________________________
> Zeek mailing list
> [email protected]
> http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek



-- 

*Patrick Kelley, CISSP, C|EH, ITIL*
*CTO*
[email protected]
(o) 770-224-6482

*The limit to which you have accepted being comfortable is the limit to
which you have grown. Accept new challenges as an opportunity to enrich
yourself and not as a point of potential failure.*

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.