<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Cortex with DeTTeCT and dettectinator in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/using-cortex-with-dettect-and-dettectinator/m-p/580850#M6348</link>
    <description>&lt;P&gt;You'll need the API keys to a functioning Cortex XDR (appID and secret), as well as the workspace URL. Have a look in the configuration file example in the repo: &lt;A href="https://github.com/themyops/pa_dettectinator/blob/main/examples/pa_datasource_config_example.json" target="_blank"&gt;https://github.com/themyops/pa_dettectinator/blob/main/examples/pa_datasource_config_example.json&lt;/A&gt;. Then run the dettectinator with the config file and it will generate the yaml file. These can be further edited with the DeTTeCT editor.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2024 21:58:49 GMT</pubDate>
    <dc:creator>Hinne.Hettema</dc:creator>
    <dc:date>2024-03-18T21:58:49Z</dc:date>
    <item>
      <title>Using Cortex with DeTTeCT and dettectinator</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/using-cortex-with-dettect-and-dettectinator/m-p/580140#M6312</link>
      <description>&lt;P&gt;I am using the DeTTeCT approach to assessing our coverage against ATT&amp;amp;CK:&amp;nbsp;&lt;A href="https://github.com/rabobank-cdc/DeTTECT" target="_blank"&gt;GitHub - rabobank-cdc/DeTTECT: Detect Tactics, Techniques &amp;amp; Combat Threats&lt;/A&gt;. In this approach, you need to start with a set of yaml files that have your datasources and detections.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have recently completed a set of PA plugins for the dettectinator project here&amp;nbsp;&lt;A href="https://github.com/themyops/pa_dettectinator" target="_blank"&gt;GitHub - themyops/pa_dettectinator: Dettectinator - The Python library to your DeTT&amp;amp;CT YAML files.&lt;/A&gt;. This is a fork of the original dettectinator project here&amp;nbsp;&lt;A href="https://github.com/siriussecurity/dettectinator" target="_blank"&gt;GitHub - siriussecurity/dettectinator: Dettectinator - The Python library to your DeTT&amp;amp;CT YAML files.&lt;/A&gt;&amp;nbsp;which has two specific Cortex XDR modules added&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. The datasources module goes through the datalake event logs and itemizes all the detected EventIDs, maps them to the OSSEM framework and gives you an inital DeTTeCT yaml file.&lt;/P&gt;
&lt;P&gt;2. The techniques module goes through the datalake and gets the techniques from the alerts tables. There are some optional parameters that will allow for a selection of fields as well as a start date.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This approach can help to get the initial yaml files from what is already available in the datalake.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 00:27:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/using-cortex-with-dettect-and-dettectinator/m-p/580140#M6312</guid>
      <dc:creator>Hinne.Hettema</dc:creator>
      <dc:date>2024-03-13T00:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: Using Cortex with DeTTeCT and dettectinator</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/using-cortex-with-dettect-and-dettectinator/m-p/580743#M6345</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218344771"&gt;@Hinne.Hettema&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you are doing well and thank you for reaching out to the Live Community. I would like to thank you for your detail explanation on how to get&amp;nbsp;&lt;SPAN&gt;yaml files. Your knowledge sharing is greatly appreciated. Thank you.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 07:56:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/using-cortex-with-dettect-and-dettectinator/m-p/580743#M6345</guid>
      <dc:creator>abdrahman</dc:creator>
      <dc:date>2024-03-18T07:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Using Cortex with DeTTeCT and dettectinator</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/using-cortex-with-dettect-and-dettectinator/m-p/580850#M6348</link>
      <description>&lt;P&gt;You'll need the API keys to a functioning Cortex XDR (appID and secret), as well as the workspace URL. Have a look in the configuration file example in the repo: &lt;A href="https://github.com/themyops/pa_dettectinator/blob/main/examples/pa_datasource_config_example.json" target="_blank"&gt;https://github.com/themyops/pa_dettectinator/blob/main/examples/pa_datasource_config_example.json&lt;/A&gt;. Then run the dettectinator with the config file and it will generate the yaml file. These can be further edited with the DeTTeCT editor.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 21:58:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/using-cortex-with-dettect-and-dettectinator/m-p/580850#M6348</guid>
      <dc:creator>Hinne.Hettema</dc:creator>
      <dc:date>2024-03-18T21:58:49Z</dc:date>
    </item>
  </channel>
</rss>

