Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added the security_control profile, removed the malware attribute #906

Merged
merged 1 commit into from
Jan 2, 2024

Conversation

pagbabian-splunk
Copy link
Contributor

Related Issue: 902

Description of changes:

Added the security_control profile to the class, removed the malware attribute with the rationale that it would only be reported when a security control product produced the Detection Finding.

Updated the class description to apply the Security Control profile under those circumstances and to copy any MITRE Attack information from the attacks attribute to finding_info so it can be made available in an Incident.

This PR will supersede PR #894 which overrode, rather than removed the malware attribute from the class.

…ntained in security_control) and updated the class description to clarify how attacks should be duplicated.

Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
@pagbabian-splunk pagbabian-splunk added documentation Improvements or additions to documentation enhancement New feature or request findings Issues related to Findings Category non_breaking Non Breaking, backwards compatible changes v1.1.0 Changes marked for v1.1.0 of OCSF labels Jan 2, 2024
Copy link
Contributor

@zschmerber zschmerber left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Contributor

@Aniak5 Aniak5 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@Aniak5 Aniak5 merged commit 544d175 into main Jan 2, 2024
2 checks passed
@floydtree floydtree deleted the det_finding_mal branch January 4, 2024 17:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation enhancement New feature or request findings Issues related to Findings Category non_breaking Non Breaking, backwards compatible changes v1.1.0 Changes marked for v1.1.0 of OCSF
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants