-
Notifications
You must be signed in to change notification settings - Fork 418
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add event.tlp #792
Comments
Can you expand on this? |
Hi @webmat TLP defines the sensitivity of information/event. So could we have add event.tlp that describe sensitivity of an event. |
@weichea Can you provide any additional context or examples of the use cases you hand in mind for capturing TLP fields? |
ping @shimonmodi - any thoughts on this from a threat intel perspective? |
@ebeahan - first of all, apologies for not responding sooner. my notification settings were off and didn't see this. thanks @jamiehynds. TLP is primarily used in incident/intelligence sharing and dissemination by industry specific sharing groups & government agencies. Essentially it dictates a contract between the sender and receiver - each of the 4 level of TLP dictate what privileges the receiver has with respect to the information being shared. Implicitly it also conveys level of sensitivity and criticality about the information being shared. With our existing capabilities I can see users:
Currently we don't support an incident/intel sharing workflow (for e.g. - company x, which belongs to financial services, has just detected a phishing attack and now wants to share their incident analysis with other financial services companies) but at some point I envision us doing so. We need to represent TLP, along with a number of other threat intelligence related fields in ECS. Just not sure if event is the right parent field for it. need to think through it. |
No worries and thanks for your insights @shimonmodi! 😄 |
@shimonmodi Seeing discussion about TLP over in #1037, I think we can close this one, right? |
I couldn't find any field for event traffic light protocol (TLP). Is there any existing field for tlp if no, could we add them?
The text was updated successfully, but these errors were encountered: