Skip to content

Commit 1fbe619

Browse files
committed
[Security Solution] Updates kibana MITRE data to v17.1 (elastic#231375)
## Summary Addresses: elastic#166152 for `9.2.0` Updates MITRE ATT&CK mappings to `v17.1`. Last update was to `v16.1` in elastic#215026. To update, I modified https://github.com/elastic/kibana/blob/1d54622d8318295d9d0509b34c1b36c811a2382e/x-pack/solutions/security/plugins/security_solution/scripts/extract_tactics_techniques_mitre.js#L22 to point to the `ATT&CK-v17.1` tag. Then ran `yarn extract-mitre-attacks` from the root `security_solution` plugin directory, and then `node scripts/i18n_check.js --fix` from Kibana root to regen the i18n files. ### Note This PR also adds guards to the test generation script so that it prevents duplicate data being generated and causing tests breaking after running this script. Another step in hopefully making this data generation and related testing entirely automated. ## Acceptance Criteria - [x] User can map and use new MITRE techniques in Security Solution - [ ] The user-facing documentation is updated with the new version - [ ] [MITRE ATT&CK® coverage](https://www.elastic.co/guide/en/security/master/rules-coverage.html) page - [ ] elastic/docs-content#2518 ## Test Criteria - [x] Verify that new techniques (see the changelog link above) are available for mapping on the Rule Creation page under "Advanced settings" - [x] Verify that new techniques are available on the MITRE ATT&CK coverage page --------- Co-authored-by: kibanamachine <[email protected]> (cherry picked from commit 1f33388) # Conflicts: # x-pack/platform/plugins/private/translations/translations/de-DE.json
1 parent 008c502 commit 1fbe619

File tree

5 files changed

+348
-87
lines changed

5 files changed

+348
-87
lines changed

x-pack/platform/plugins/private/translations/translations/fr-FR.json

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -37119,8 +37119,6 @@
3711937119
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.diskContentWipeT1561Description": "Effacement du contenu du disque (T1561.001)",
3712037120
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.diskStructureWipeT1561Description": "Effacement de la structure du disque (T1561.002)",
3712137121
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.distributedComponentObjectModelT1021Description": "Modèle d'objet du composant distribué (T1021.003)",
37122-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dllSearchOrderHijackingT1574Description": "Piratage de l'ordre de recherche des DLL (T1574.001)",
37123-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dllSideLoadingT1574Description": "Chargement latéral des DLL (T1574.002)",
3712437122
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dnsCalculationT1568Description": "Calcul DNS (T1568.003)",
3712537123
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dnsPassiveDnsT1596Description": "DNS/DNS passif (T1596.001)",
3712637124
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dnsServerT1583Description": "Serveur DNS (T1583.002)",
@@ -37249,7 +37247,6 @@
3724937247
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.markOfTheWebBypassT1553Description": "Contournement Mark-of-the-Web (T1553.005)",
3725037248
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.masqueradeFileTypeT1036Description": "Type de fichier de mascarade (T1036.008)",
3725137249
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.masqueradeTaskOrServiceT1036Description": "Tâche ou service de mascarade (T1036.004)",
37252-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.matchLegitimateNameOrLocationT1036Description": "Correspondance de nom ou d'emplacement légitime (T1036.005)",
3725337250
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.mavinjectT1218Description": "Mavinject (T1218.013)",
3725437251
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.mmcT1218Description": "MMC (T1218.014)",
3725537252
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.modifyCloudComputeConfigurationsT1578Description": "Modifier les configurations de l'informatique cloud (T1578.005)",
@@ -37320,7 +37317,6 @@
3732037317
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.remoteDataStagingT1074Description": "Mise en service de données distantes (T1074.002)",
3732137318
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.remoteDesktopProtocolT1021Description": "Protocole de bureau distant (T1021.001)",
3732237319
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.remoteEmailCollectionT1114Description": "Collection d'e-mails distants (T1114.002)",
37323-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.renameSystemUtilitiesT1036Description": "Renommage d'utilitaires système (T1036.003)",
3732437320
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.reOpenedApplicationsT1547Description": "Réouverture d'applications (T1547.007)",
3732537321
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.resourceForkingT1564Description": "Fourchettes de ressources (T1564.009)",
3732637322
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.reversibleEncryptionT1556Description": "Chiffrement réversible (T1556.005)",
@@ -37474,7 +37470,6 @@
3747437470
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bitsJobsDescription": "Tâches BITS (T1197)",
3747537471
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bootOrLogonAutostartExecutionDescription": "Exécution de démarrage ou de démarrage automatique de connexion (T1547)",
3747637472
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bootOrLogonInitializationScriptsDescription": "Scripts de démarrage ou d'initialisation de connexion (T1037)",
37477-
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.browserExtensionsDescription": "Extensions de navigateur (T1176)",
3747837473
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.browserInformationDiscoveryDescription": "Découverte d'informations de navigateur (T1217)",
3747937474
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.browserSessionHijackingDescription": "Détournement de session de navigateur (T1185)",
3748037475
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bruteForceDescription": "Force brute (T1110)",
@@ -37602,7 +37597,6 @@
3760237597
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.proxyDescription": "Proxy (T1090)",
3760337598
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.queryRegistryDescription": "Interrogation du registre (T1012)",
3760437599
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.reflectiveCodeLoadingDescription": "Chargement de code réflexif (T1620)",
37605-
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteAccessSoftwareDescription": "Logiciel d'accès à distance(T1219)",
3760637600
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteServicesDescription": "Services distants (T1021)",
3760737601
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteServiceSessionHijackingDescription": "Piratage de session de service distant (T1563)",
3760837602
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteSystemDiscoveryDescription": "Découverte de système distant (T1018)",

x-pack/platform/plugins/private/translations/translations/ja-JP.json

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -37090,8 +37090,6 @@
3709037090
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.diskContentWipeT1561Description": "ディスク内容のワイプ(T1561.001)",
3709137091
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.diskStructureWipeT1561Description": "ディスク構造のワイプ(T1561.002)",
3709237092
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.distributedComponentObjectModelT1021Description": "分散コンポーネントオブジェクトモデル(T1021.003)",
37093-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dllSearchOrderHijackingT1574Description": "DLL 検索順序ハイジャック(T1574.001)",
37094-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dllSideLoadingT1574Description": "DLL サイドロード(T1574.002)",
3709537093
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dnsCalculationT1568Description": "DNS 計算(T1568.003)",
3709637094
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dnsPassiveDnsT1596Description": "DNS/パッシブ DNS(T1596.001)",
3709737095
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dnsServerT1583Description": "DNS サーバー(T1583.002)",
@@ -37220,7 +37218,6 @@
3722037218
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.markOfTheWebBypassT1553Description": "Mark-of-the-Webバイパス (T1553.005)",
3722137219
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.masqueradeFileTypeT1036Description": "マスカレードファイルタイプ(T1036.008)",
3722237220
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.masqueradeTaskOrServiceT1036Description": "マスカレードタスクまたはサービス(T1036.004)",
37223-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.matchLegitimateNameOrLocationT1036Description": "合法的な名前または場所と一致(T1036.005)",
3722437221
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.mavinjectT1218Description": "Mavinject (T1218.013)",
3722537222
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.mmcT1218Description": "MMC (T1218.014)",
3722637223
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.modifyCloudComputeConfigurationsT1578Description": "クラウドコンピューティング構成の修正(T1578.005)",
@@ -37291,7 +37288,6 @@
3729137288
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.remoteDataStagingT1074Description": "データステージングの削除(T1074.002)",
3729237289
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.remoteDesktopProtocolT1021Description": "リモートデスクトッププロトコル(T1021.001)",
3729337290
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.remoteEmailCollectionT1114Description": "リモート電子メール収集(T1114.002)",
37294-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.renameSystemUtilitiesT1036Description": "システムユーティリティ名の変更(T1036.003)",
3729537291
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.reOpenedApplicationsT1547Description": "再オープンされたアプリケーション(T1547.007)",
3729637292
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.resourceForkingT1564Description": "リソースフォーク(T1564.009)",
3729737293
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.reversibleEncryptionT1556Description": "解読可能な暗号化(T1556.005)",
@@ -37445,7 +37441,6 @@
3744537441
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bitsJobsDescription": "BITSジョブ(T1197)",
3744637442
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bootOrLogonAutostartExecutionDescription": "ブートまたはログオン自動起動実行(T1547)",
3744737443
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bootOrLogonInitializationScriptsDescription": "ブートまたはログオン初期化スクリプト(T1037)",
37448-
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.browserExtensionsDescription": "ブラウザー拡張(T1176)",
3744937444
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.browserInformationDiscoveryDescription": "ブラウザー情報検出(T1217)",
3745037445
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.browserSessionHijackingDescription": "ブラウザーセッションハイジャック(T1185)",
3745137446
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bruteForceDescription": "Brute Force(T1110)",
@@ -37573,7 +37568,6 @@
3757337568
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.proxyDescription": "プロキシ(T1090)",
3757437569
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.queryRegistryDescription": "クエリレジストリ(T1012)",
3757537570
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.reflectiveCodeLoadingDescription": "Reflective Code Loading(T1620)",
37576-
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteAccessSoftwareDescription": "リモートアクセスソフトウェア(T1219)",
3757737571
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteServicesDescription": "リモートサービス(T1021)",
3757837572
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteServiceSessionHijackingDescription": "リモートサービスセッションハイジャック(T1563)",
3757937573
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteSystemDiscoveryDescription": "リモートシステム検出(T1018)",

x-pack/platform/plugins/private/translations/translations/zh-CN.json

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -37153,8 +37153,6 @@
3715337153
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.diskContentWipeT1561Description": "Disk Content Wipe (T1561.001)",
3715437154
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.diskStructureWipeT1561Description": "Disk Structure Wipe (T1561.002)",
3715537155
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.distributedComponentObjectModelT1021Description": "Distributed Component Object Model (T1021.003)",
37156-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dllSearchOrderHijackingT1574Description": "DLL Search Order Hijacking (T1574.001)",
37157-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dllSideLoadingT1574Description": "DLL Side-Loading (T1574.002)",
3715837156
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dnsCalculationT1568Description": "DNS Calculation (T1568.003)",
3715937157
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dnsPassiveDnsT1596Description": "DNS/Passive DNS (T1596.001)",
3716037158
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.dnsServerT1583Description": "DNS Server (T1583.002)",
@@ -37283,7 +37281,6 @@
3728337281
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.markOfTheWebBypassT1553Description": "Mark-of-the-Web Bypass (T1553.005)",
3728437282
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.masqueradeFileTypeT1036Description": "Masquerade File Type (T1036.008)",
3728537283
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.masqueradeTaskOrServiceT1036Description": "Masquerade Task or Service (T1036.004)",
37286-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.matchLegitimateNameOrLocationT1036Description": "Match Legitimate Name or Location (T1036.005)",
3728737284
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.mavinjectT1218Description": "Mavinject (T1218.013)",
3728837285
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.mmcT1218Description": "MMC (T1218.014)",
3728937286
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.modifyCloudComputeConfigurationsT1578Description": "Modify Cloud Compute Configurations (T1578.005)",
@@ -37354,7 +37351,6 @@
3735437351
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.remoteDataStagingT1074Description": "Remote Data Staging (T1074.002)",
3735537352
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.remoteDesktopProtocolT1021Description": "Remote Desktop Protocol (T1021.001)",
3735637353
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.remoteEmailCollectionT1114Description": "Remote Email Collection (T1114.002)",
37357-
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.renameSystemUtilitiesT1036Description": "Rename System Utilities (T1036.003)",
3735837354
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.reOpenedApplicationsT1547Description": "Re-opened Applications (T1547.007)",
3735937355
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.resourceForkingT1564Description": "Resource Forking (T1564.009)",
3736037356
"xpack.securitySolution.detectionEngine.mitreAttackSubtechniques.reversibleEncryptionT1556Description": "Reversible Encryption (T1556.005)",
@@ -37508,7 +37504,6 @@
3750837504
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bitsJobsDescription": "BITS Jobs (T1197)",
3750937505
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bootOrLogonAutostartExecutionDescription": "Boot or Logon Autostart Execution (T1547)",
3751037506
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bootOrLogonInitializationScriptsDescription": "Boot or Logon Initialization Scripts (T1037)",
37511-
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.browserExtensionsDescription": "Browser Extensions (T1176)",
3751237507
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.browserInformationDiscoveryDescription": "Browser Information Discovery (T1217)",
3751337508
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.browserSessionHijackingDescription": "Browser Session Hijacking (T1185)",
3751437509
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.bruteForceDescription": "Brute Force (T1110)",
@@ -37636,7 +37631,6 @@
3763637631
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.proxyDescription": "Proxy (T1090)",
3763737632
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.queryRegistryDescription": "Query Registry (T1012)",
3763837633
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.reflectiveCodeLoadingDescription": "Reflective Code Loading (T1620)",
37639-
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteAccessSoftwareDescription": "Remote Access Software (T1219)",
3764037634
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteServicesDescription": "Remote Services (T1021)",
3764137635
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteServiceSessionHijackingDescription": "Remote Service Session Hijacking (T1563)",
3764237636
"xpack.securitySolution.detectionEngine.mitreAttackTechniques.remoteSystemDiscoveryDescription": "Remote System Discovery (T1018)",

0 commit comments

Comments
 (0)