Skip to content

Commit

Permalink
Update index.md
Browse files Browse the repository at this point in the history
  • Loading branch information
alexiacrumpton authored Jan 9, 2024
1 parent 83bf2b0 commit bfb707f
Showing 1 changed file with 2 additions and 13 deletions.
15 changes: 2 additions & 13 deletions docs/coverage/index.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,7 @@
---
title: Analytic Coverage Comparison
---
Generated on: December 30, 2022
=======

Generated on: January 08, 2024

A cross-walk of CAR, [Sigma](https://github.com/SigmaHQ/sigma), [Elastic Detection](https://github.com/elastic/detection-rules), and [Splunk Security Content](https://github.com/splunk/security_content/tree/develop/detections) rules in terms of their coverage of ATT&CK Techniques and Sub-techniques. Note that some analytics may have coverage for multiple techniques, so there is not necessarily a 1:1 correlation between the number of hits in this table for a technique/sub-technique and the number of analytics in each repository. The below table is current as of the Generated On date at the top of this page.
Expand All @@ -15,24 +14,14 @@ Generated on: December 30, 2022

This table is sortable, so feel free to click on any column to sort by its values. Clicking on each of the CAR/Sigma/ES/Splunk results will search the corresponding repository for the analytics that contain coverage for the technique/sub-technique.

This data is also available
* A [CSV file](/coverage/analytic_coverage_12_30_2022.csv).
* Separate ATT&CK Navigator Layers:
* [CAR Analytic Coverage](https://mitre-attack.github.io/attack-navigator/#layerURL=https://raw.githubusercontent.com/mitre-attack/car/master/docs/coverage/car_analytic_coverage_12_30_2022.json).
* [Sigma Analytic Coverage](https://mitre-attack.github.io/attack-navigator/#layerURL=https://raw.githubusercontent.com/mitre-attack/car/master/docs/coverage/es_analytic_coverage_12_30_2022.json).
* [ES Analytic Coverage](https://mitre-attack.github.io/attack-navigator/#layerURL=https://raw.githubusercontent.com/mitre-attack/car/master/docs/coverage/es_analytic_coverage_12_30_2022.json).
* [Splunk Analytic Coverage](https://mitre-attack.github.io/attack-navigator/#layerURL=https://raw.githubusercontent.com/mitre-attack/car/master/docs/coverage/splunk_analytic_coverage_12_30_2022.json).
This data is also available as:

<script type="text/javascript" src="/assets/sort-table.js"></script>
<table class="js-sort-table" id="coverage-sort">
=======
* A [CSV file](/coverage/analytic_coverage_01_08_2024.csv).
* Separate ATT&CK Navigator Layers:
* [CAR Analytic Coverage](https://mitre-attack.github.io/attack-navigator/#layerURL=https://raw.githubusercontent.com/mitre-attack/car/master/docs/coverage/car_analytic_coverage_01_08_2024.json).
* [Sigma Analytic Coverage](https://mitre-attack.github.io/attack-navigator/#layerURL=https://raw.githubusercontent.com/mitre-attack/car/master/docs/coverage/es_analytic_coverage_01_08_2024.json).
* [ES Analytic Coverage](https://mitre-attack.github.io/attack-navigator/#layerURL=https://raw.githubusercontent.com/mitre-attack/car/master/docs/coverage/es_analytic_coverage_01_08_2024.json).
* [Splunk Analytic Coverage](https://mitre-attack.github.io/attack-navigator/#layerURL=https://raw.githubusercontent.com/mitre-attack/car/master/docs/coverage/splunk_analytic_coverage_01_08_2024.json).

<script type="text/javascript" src="/assets/sort-table.js"></script>
<table class="js-sort-table" id="coverage-so
<thead>
Expand Down

0 comments on commit bfb707f

Please sign in to comment.