Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add TTPs directily on Edge details #180

Open
theoberthier opened this issue Mar 28, 2024 · 3 comments
Open

Add TTPs directily on Edge details #180

theoberthier opened this issue Mar 28, 2024 · 3 comments
Labels
enhancement New feature or request

Comments

@theoberthier
Copy link

Hello !
Thank's for the great tool !
When I tested the tool, I saw that the kubehound attacks (TTPs) were not linked directly in the Janus Graph database.

I suggest adding TTPs directly to the Edges details.

If we want to browse the Janus graph data or link the Janus graph with data from another security tool to trace or automate attacks or propose mitigations.

In these cases it's intressting to add the TTP reference directly to the edges.

@jt-dd
Copy link
Contributor

jt-dd commented Apr 9, 2024

You are referring to the information listed in kubehound.io (for instance, Escape to Host, T1611 for CE_NSENTER edge) ?

If so that is a great idea, and will try to include it in the next release as property of the edges.

@theoberthier
Copy link
Author

Yes it's MITTRE attack TTPs ID which are specified in your attack reference

@theoberthier
Copy link
Author

It's a good idea to add it to both databases, so that when another security tool wants to obtain this information, it will do so via the Mongo database or the Graph database.
Why ? because gremlin synthax or kubehound dsl are more complexe than mongodb query with SDK in many language.

@jt-dd jt-dd added the enhancement New feature or request label Sep 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants