cd .. (Geri Dön)
siem-kutuphanesi/detection-use-cases/detection-use-cases-linux.md

Linux

ATT&CK ile eşlenen denetim yapılandırması

Orta SeviyeT1059.004T1053.003T1548.001T1070.002T1037SyslogAuditdSystemd Journalosquery

ATT&CK ile eşlenen denetim yapılandırması

https://github.com/bfuzzy/auditd-attack →

https://github.com/bfuzzy/auditd-attack

*NIX sistemleri için LOL kutuları

https://gtfobins.org/ →

https://gtfobins.org/

Florian Roth'un denetim yapılandırması

https://gist.github.com/Neo23x0/9fe88c0c5979e017a389b90fd19ddfee →

https://gist.github.com/Neo23x0/9fe88c0c5979e017a389b90fd19ddfee

Linux için ATT&CK tekniklerini ve taktiklerini tespit etmek

https://github.com/Kirtar22/Litmus_Test/blob/master/README.md →

https://github.com/Kirtar22/Litmus_Test/blob/master/README.md

Linux için Sysmon

https://github.com/microsoft/MSTIC-Sysmon/tree/main/linux/configs →

https://github.com/microsoft/MSTIC-Sysmon/tree/main/linux/configs

https://www.lares.com/blog/sysmon-for-linux-test-drive/ →

https://www.lares.com/blog/sysmon-for-linux-test-drive/

sebat →

Linux'ta kalıcılık mekanizmalarını tespit etmek

https://pberba.github.io/security/2021/11/22/linux-threat-hunting-for-persistence-sysmon-auditd-webshell/ →

https://pberba.github.io/security/2021/11/22/linux-threat-hunting-for-persistence-sysmon-auditd-webshell/

https://pberba.github.io/security/2021/11/23/linux-threat-hunting-for-persistence-account-creation-manipulation/ →

https://pberba.github.io/security/2021/11/23/linux-threat-hunting-for-persistence-account-creation-manipulation/

INTERACTIVE_TOOLS.sh
Siber Güvenlik Test & Analiz Araçları
$./soc-maturity-test.sh

Kurumunuzun güvenlik operasyon merkezi (SOC) olgunluk seviyesini, tehdit algılama ve müdahale (MTTD/MTTR) sürelerini hızlıca ölçün.

[ TESTİ BAŞLAT ]
$./mitre-attack-coverage.sh

SIEM kullanım senaryolarımızın MITRE ATT&CK matrisi üzerindeki kapsamını ve ısı haritasını (taktik/teknik eşleşmelerini) interaktif görün.

[ MATRİSİ İNCELE ]
SIGMA_RULES.yml

İlgili Sigma Algılama Kuralları

Bu senaryoyla ilişkili 2 adet Sigma kuralı bulundu. Kuralları genişleterek YAML formatında görebilir, kopyalayabilir veya SIEM formatına dönüştürebilirsiniz.

🛡️ INTEGRATION.md

ACKLOG SIEM İle Tam Entegrasyon

Bu dokümantasyonda listelenen log kaynakları, kurallar, korelasyon mantıkları ve tespit senaryoları ACKLOG SIEM ürün ailesi tarafından yerleşik olarak desteklenmektedir. ACKLOG, teknolojisi ve otomasyon modülleri ile tespit süreçlerinizi saniyeler içinde devreye almanızı sağlar.