Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ability to sort a dashboard contents by MITRE kill chain #138256

Open
sekretskwirl opened this issue Aug 8, 2022 · 1 comment
Open

Ability to sort a dashboard contents by MITRE kill chain #138256

sekretskwirl opened this issue Aug 8, 2022 · 1 comment
Labels
Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Comments

@sekretskwirl
Copy link

I am hoping to sort the MITRE Tactics Dashboard columns below according to the MITRE Kill Chain sequence. The progression of an attack through the Kill Chain Tactics is left to right and this is the order I want the dashboard in, from left to right.

Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact

The attached dashboard shows our alerts broken down by MITRE Tactic. It would be very useful to see these in the correct order of the kill chain because this is how we teach new SOC analysts to recognize Triage priority; work the alerts from right to left. It also provides the SOC manager a quick visualization of the alert environment by kill chain progession.

MITRE Alerts by Kill Chain

@botelastic botelastic bot added the needs-team Issues missing a team label label Aug 8, 2022
@marius-dr marius-dr added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Aug 12, 2022
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@botelastic botelastic bot removed the needs-team Issues missing a team label label Aug 12, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Projects
None yet
Development

No branches or pull requests

3 participants