Related note 0
Related note 1
Related note 2
Related note 3
Events
Events catalog
List of BlackNoise events that can be included within scenarios.
Events Library in table form
Events Library in table form
The table presents the following information for all the events that are available:
Event
type
(
network
,
windows
,
linux
or
macos
)
Default
severity
(red =
high
, yellow =
low
)
Event
name
Availability of a
Sigma
rule
MITRE ATT&CK
tactic
MITRE ATT&CK
technique ID
By clicking on the name of an event, you can view all associated information, including its description.
Hint:
The link present on the MITRE ATT&CK technique reference opens the MITRE description web page associated with this technique
To facilitate the operation of the event list, several features are available:
Display order
by name (A=>Z, Z=>A)
Application of
filters
: according to default severity, event type, MITRE AT&CK Tactic and availability of a Sigma rule
Search
field
Display
of events in table or in MITRE ATT&CK matrix form
Events Library in MITRE ATT&CK Matrix form
Events Library in MITRE ATT&CK Matrix form