-
Notifications
You must be signed in to change notification settings - Fork 347
Data sources per platform
Content:
The below mapping from data sources/data components to platforms is created on the information provided by MITRE within the data source objects. Also, note that the below is only listing data components that are actually referenced by a technique. Therefore it does not include all data components as referenced in the STIX repository.
The below mapping from data sources/data components to platforms is created on the information provided by MITRE within the data source objects. Also, note that the below is only listing data components that are actually referenced by a technique. Therefore it does not include all data components as referenced in the STIX repository.
At this moment we do not have any DeTT&CT data sources for Mobile. If there is a need or if you do have a suggestion, we will look into this.
| Data source | Android | iOS |
|---|---|---|
| API Calls | X | X |
| Application Assets | X | X |
| Command Execution | X | X |
| Host Status | X | X |
| Network Communication | X | X |
| Network Connection Creation | X | X |
| Network Traffic Content | X | X |
| Network Traffic Flow | X | X |
| OS API Execution | X | X |
| Permissions Request | X | X |
| Permissions Requests | X | X |
| Process Creation | X | X |
| Process Metadata | X | X |
| Process Termination | X | |
| Protected Configuration | X | X |
| System Notifications | X | X |
| System Settings | X | X |
Official platform mapping is missing
An official mapping for ICS sources/data components to platforms is currently missing. Since v14 release of ATT&CK platforms are not being used anymore for ICS. Therefor we cannot generate data source - platform mappings for ICS.
As we do not consider ourselves experts in the field of ICS, we have not included the DeTT&CT data sources. Any help and thus contributions on that matter are very much appreciated. Possibly, with future developments of ATT&CK ICS, we could automate this part when Detection objects are introduced. However, it is not certain whether this will provide good results.
- Home
- Introduction
- Installation and requirements
- Getting started / How to
- Changelog
- Future developments
- ICS - Inconsistencies
- Introduction
- DeTT&CT data sources
- Data sources per platform
- Data quality
- Scoring data quality
- Improvement graph