[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: Re: [cacao] RE: [EXT] [cacao] Playbook Functionalities
I had a proposal for a name in the metadata doc that was getting added.AllanOn Nov 19, 2022, at 2:59 PM, Dr. Desiree A Beck <dbeck@mitre.org> wrote:ïBret,
I think this looks great. I think a dictionary works well and that itâs a good idea to tie together functionalities and types.
I agree that we might want to change the property nameâ I like âplaybook_characteristicsâ or maybe âplaybook_attributes.â
Dez
Â
From: cacao@lists.oasis-open.org <cacao@lists.oasis-open.org> On Behalf Of Bret Jordan
Sent: Saturday, November 19, 2022 10:22 AM
To: cacao@lists.oasis-open.org
Subject: [EXT] [cacao] Playbook FunctionalitiesÂ
All,
Â
Based on the proposal from Marlon, that several people have supported we have the following:
Â
playbook_types is optionalÂwith a normative SHOULD use
playbook_functionalities is optional withÂa normate SHOULD use & a normative MUST use if playbook_types is used.
Â
This gives us potential of having something like:
Â
{
 "type": "playbook",
 "spec_version": "cacao-1.1",
 "id": "playbook--91220064-3c6f-4b58-99e9-196e64f9bde7",
 "name": "Find Malware FuzzyPanda",
 "description": "This playbook will look for FuzzyPanda on the network and in a SIEM",
 "playbook_types": ["investigation", "detection"],
 "playbook_functionalities": ["analyze-collected-data", "identify-indicators", "scan-system"],....
}
Â
I am wondering if playbook_types and playbook_functionalties should be combined to something like:
Â
{
 "type": "playbook",
 "spec_version": "cacao-1.1",
 "id": "playbook--91220064-3c6f-4b58-99e9-196e64f9bde7",
 "name": "Find Malware FuzzyPanda",
 "description": "This playbook will look for FuzzyPanda on the network and in a SIEM",
 "playbook_types": {  "investigation": ["analyze-collected-data", "identify-indicators"],
  "detection": ["scan-system"]
 },
....}
Â
I basically changed playbook_types from a list to a dictionary. Would something like this help?
Â
And if we do not like the playbook_types name with the combined data it could be changed to something else. Maybe characteristicsÂor something. Dez, Rich, Marlon? Do we want to try and tie the functionalities to the type being used?
Â
Bret
Â
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]