5. Working with the data
In this chapter we are going to review how to work with the data to document security events in a way that will allow us to hunt effectively for them. The goal behind this approach is to gain the ability to understand the data we are collecting and have everything documented in a way that will allow us to have an idea of what can we hunt for and which data maybe missing from our collection process. First, we are going to cover two data models that can be used to better understand our data sources: OSSEM data dictionaries and MITRE CAR. Then, we are going to close the chapter reviewing Sigma rules: an open signature format that can be applied to any log file and that can be used to describe and share detections.
- Using data dictionaries
- Using MITRE CAR
- Using Sigma