Relationship between Detections and Atomic Red Team test cases (or other test case library) #2249
jbrianmoss
started this conversation in
General
Replies: 1 comment 2 replies
-
If this is better place as a question to Splunk Support, please let me know and we can go that route instead. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Good morning, I am wondering if there is a mapping kept between Detections and an Atomic Red Team test case(s)? I was half expecting this to be a tag in the Detection's YAML file, but it appears the only reference is in the free text description of the Detection and not consistently for all Detections. I see that the Cyber Range supports Atomic Red Team so maybe this mapping might existing somewhere else?
If this mapping does not exist anywhere, the a follow-up question would be if there are any suggestions on how best to implement the mapping in a way that would be acceptable to the project's maintainers. We are currently thinking we would need to create this mapping, and if that is the case we would like to do it in such a way that it could help the community.
Kind Regards,
Brian
Beta Was this translation helpful? Give feedback.
All reactions