elastic / elastic/detection-rules

[FR] Align "Data Source" tags with MITRE

オープン
#3,290 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
backlog community enhancement
主要言語
Python
スター
2.7k
フォーク
696
平均マージ
5日 1時間
マージ済み PR(30日)
72

説明

**Is your feature request related to a problem? Please describe.**
I feel like aligning the `Data Source` tags with the [MITRE Data Sources](https://attack.mitre.org/datasources/) suppliments
the existing MITRE ATT&CK mappings. Further building on an existing framework.

**Describe the solution you'd like**
Allow the `Data Source` tags to have the name of the sources mentioned in [MITRE](https://attack.mitre.org/datasources/).
E.g:
```
tags = ["Data Source: Container"]
```

**Describe alternatives you've considered**
Manually updating the definition file in our repository.

**Additional context**
I don't believe it should be 100% mapped. As in only those values should be allowed. But I do think the rules where possible
should have them tagged and custom rules should have the option.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。