OASIS Open Mailing List Archives  ·  All Lists  ·  cti-stix  ·  2016-06

cti-stix — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Re: [cti-stix] Including Incident and Assets in STIX MVP


Our organization receives incident information as the primary type of information that is sent as part of the sharing initiative that we run. Incidents provide the context associated with a observations. A SOC can easily communicate everything that happens within an Incident. That information is placed in observations and are associated with kill chain phases. The incident ties all of this together. Either a SOC or a cyber analytics team can take that information and create indicators based upon the observations associated with the incident. The incident data can be useful for trending, determining TTPs or volatility. It's very useful for performing attribution back to an intrusion set or threat actor. We wouldn't want to tie Observations directly back to an Intrusion Set or Campaign, we want to tie back an Incident. If I have 10 observations directly tied to a Campaign its difficult to know if they were part of the same incident, were they separate observations of just different parts of the campaign. -Gary

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]