Skip to content

Commit

Permalink
Custom queries for mitre (flow alerts)
Browse files Browse the repository at this point in the history
  • Loading branch information
cardigliano committed Aug 6, 2024
1 parent 575f955 commit 2367402
Show file tree
Hide file tree
Showing 3 changed files with 108 additions and 0 deletions.
36 changes: 36 additions & 0 deletions scripts/historical/alerts/flow/mitre_id.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
{
"name" : "Mitre Attacks",
"i18n_name" : "",
"select" : {
"items" : [
{
"name" : "mitre_id"
},
{
"name" : "count",
"func" : "COUNT",
"param" : "*",
"value_type" : "number"
}
]
},
"filters" : {
"items" : [
]
},
"groupby" : {
"items" : [
{
"name" : "mitre_id"
}
]
},
"sortby" : {
"items" : [
{
"name" : "count",
"order" : "DESC"
}
]
}
}
36 changes: 36 additions & 0 deletions scripts/historical/alerts/flow/mitre_tactic.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
{
"name" : "Mitre Tactics",
"i18n_name" : "",
"select" : {
"items" : [
{
"name" : "mitre_tactic"
},
{
"name" : "count",
"func" : "COUNT",
"param" : "*",
"value_type" : "number"
}
]
},
"filters" : {
"items" : [
]
},
"groupby" : {
"items" : [
{
"name" : "mitre_tactic"
}
]
},
"sortby" : {
"items" : [
{
"name" : "count",
"order" : "DESC"
}
]
}
}
36 changes: 36 additions & 0 deletions scripts/historical/alerts/flow/mitre_technique.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
{
"name" : "Mitre Techniques",
"i18n_name" : "",
"select" : {
"items" : [
{
"name" : "mitre_technique"
},
{
"name" : "count",
"func" : "COUNT",
"param" : "*",
"value_type" : "number"
}
]
},
"filters" : {
"items" : [
]
},
"groupby" : {
"items" : [
{
"name" : "mitre_technique"
}
]
},
"sortby" : {
"items" : [
{
"name" : "count",
"order" : "DESC"
}
]
}
}

0 comments on commit 2367402

Please sign in to comment.