View intrusion events

This task allows you to view MITRE ATT&CK techniques and rule groups associated with intrusion events, providing security context and attack pattern mapping for better threat analysis.

You can view the MITRE ATT&CK techniques and rule groups in the intrusion events on the Classic Event Viewer and Unified Event Viewer pages. Talos provides mappings from Snort rules (GID:SID) to MITRE ATT&CK techniques and rule groups. These mappings are installed as part of the Lightweight Security Package (LSP).

Procedure


Step 1

Click Analysis and select Events under Intrusions.

Step 2

Click the Table View of Events tab.

The image illustrates the mapping of Snort rules to MITRE ATT&CK techniques and rule groups, highlighting how intrusion events are categorized in the Classic and Unified Event Viewer pages.

Step 3

Under MITRE ATT&CK, you can see the techniques for an intrusion event. Click 1 Technique to view the MITRE ATT&CK techniques.

The diagram illustrates the process of exploiting a public-facing application, highlighting the steps involved in the intrusion event.

In this example, Exploit Public-Facing Application is the technique.

The diagram illustrates the process of exploiting a public-facing application, highlighting the steps involved in the attack and the potential vulnerabilities that can be targeted.

Step 4

Click Close.

Step 5

Click Analysis and select Unified Events.

Step 6

If not enabled, click the column selector icon to enable the MITRE ATT&CK and Rule Group columns.

The image illustrates a timeline of intrusion events, highlighting key incidents and their timestamps for analysis. It provides a visual representation of the frequency and types of intrusions detected over a specified period.

Step 7

In this example, the intrusion event is triggered by an event that is mapped to one rule group. Click 1 Group under the Rule Group column.

The search results display a list of intrusion events, highlighting key details such as event type, timestamp, and affected systems.

Step 8

You can view Protocol, which is the parent rule group, and the DNS rule group under it. Choose Protocol > DNS to search for all the intrusion events that have at least one rule group.

The search results display the MITRE ATT&CK techniques and rule groups linked to intrusion events, highlighting the security context and attack patterns for enhanced threat analysis.

The search results are displayed.

The search results display the MITRE ATT&CK techniques and rule groups linked to intrusion events, highlighting the security context and attack patterns for enhanced threat analysis.