elastic / elastic/detection-rules
[FR] Align "Data Source" tags with MITRE
- 主要言語
- Python
- スター
- 2.7k
- フォーク
- 696
- 平均マージ
- 5日 1時間
- マージ済み PR(30日)
- 72
説明
**Is your feature request related to a problem? Please describe.**
I feel like aligning the `Data Source` tags with the [MITRE Data Sources](https://attack.mitre.org/datasources/) suppliments
the existing MITRE ATT&CK mappings. Further building on an existing framework.
**Describe the solution you'd like**
Allow the `Data Source` tags to have the name of the sources mentioned in [MITRE](https://attack.mitre.org/datasources/).
E.g:
```
tags = ["Data Source: Container"]
```
**Describe alternatives you've considered**
Manually updating the definition file in our repository.
**Additional context**
I don't believe it should be 100% mapped. As in only those values should be allowed. But I do think the rules where possible
should have them tagged and custom rules should have the option.
コントリビューションガイド
評価
この issue はまだ評価されていません。