Giter VIP home page Giter VIP logo

rapid-response-reporting's Introduction

#Rapid-Response-Reporting 🔮RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provide accurate and timely feedback in the form of reports.

🤠BLUF: If your organization has a malware incident, based upon the malware family, you can quickly find: 🚨Mitigating Controls 🥳Recommendations 🚩Data Sources

🧐How does it work?:

Based upon the Malware family I collected the Mitre Att&CK TTPs and then pivoted to the defensive measures, data sources for detecting, and recommendations and joined those all into unique objects.

🤌These are provided in two formats:

  1. CSV - Need to give a quick update without a report? This works for you.
  2. Sankey Images - These vectorized graphics show "biggest bang for your buck" for each malware family. -> Moving left to right you have 🥇1. Defensive Control 🥈2. The concerned technique 🥉3. Data source required to detect said technique.

image

🙃BONUS: If you want the data in a preformatted Word Doc table that you can copy and paste simply run Create-Recommendations.

😍Due credits: I got this idea from Andy Applebaum and Jamie Williams and the rest of the ATT&CK team based upon a series of blog post from back in 2019: https://medium.com/mitre-attack/visualizing-attack-f5e1766b42a6 While it isn't an entirely novel idea (see the blog), it is the most complete corpus of malware family documents that I have found to date.

🤝Also this data was generated based off of https://github.com/nshalabi/ATTACK-Tools/. Without @nshalabi's sql database, joining this data would have been much more difficult.

🚧Caution: These were generated at a point in time and not evergreen. Make sure to double check the output to ensure that it meets your needs and is taking into account any changes in the MITRE ATT&CK framework and/or developements in malware capabilities. Regardles, they will get you really close and save you a bunch of time...which is the point.

🗿Why release them now:? I previously worked for many years in a DFIR/CSIRT capability. I now am working as a Senior Threat Researcher and it felt selfish to sit on this set of data.

👎I've also included my terrible Powershell script I used to produce them. It wasn't ever intended to see the light of day so I didn't follow any standards so please don't judge me.

rapid-response-reporting's People

Contributors

pfpt-andrew avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.