Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FAQ - OCSF relation to STIX #28

Open
jetlime opened this issue Apr 5, 2023 · 1 comment
Open

FAQ - OCSF relation to STIX #28

jetlime opened this issue Apr 5, 2023 · 1 comment

Comments

@jetlime
Copy link

jetlime commented Apr 5, 2023

I am currently trying to understand how OCSF compares to STIX. I noticed in the present FAQ (https://github.com/ocsf/ocsf-docs/tree/main/FAQs) that you planned to add an explanation on how they are complementary.
As I cannot seem to find an answer to my question online, would it be possible to obtain one here?

Thanks.

@pagbabian-splunk
Copy link
Contributor

I think the best person to elaborate on this would be @JasonKeirstead . In short, STIX IOCs can be matched against OCSF observables to match possible attack vectors from known threat actors. There is an overlap in concept as STIX also distinguishes observables (from where OCSF borrowed the name), from IOCs, which are those observables and other artifacts that match threat vectors.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants