SIEM

Tables and their fields are listed below.

Monitored Groups

Groups

(To append to MITRE Groups those not covered)

Relationships

(To append to MITRE Relationships those not covered)

Log Sources

Indicator of Compromise

Systems

Users

Playbooks

Signatures

Settings

Hunts

Hunt Backlog

Incidents

MITRE Attack Techniques

(from MITRE (https://attack.mitre.org/resources/attack-data-and-tools/))

MITRE Tactics

(from MITRE (https://attack.mitre.org/resources/attack-data-and-tools/))

MITRE Software

(from MITRE (https://attack.mitre.org/resources/attack-data-and-tools/))

MITRE Groups

(from MITRE (https://attack.mitre.org/resources/attack-data-and-tools/))

MITRE Campaigns

(from MITRE (https://attack.mitre.org/resources/attack-data-and-tools/))

MITRE Mitigations

(from MITRE (https://attack.mitre.org/resources/attack-data-and-tools/))

MITRE Relationships

(from MITRE (https://attack.mitre.org/resources/attack-data-and-tools/))

MITRE Datasources

(from MITRE (https://attack.mitre.org/resources/attack-data-and-tools/))

Sigma as CSV

(From https://github.com/TonyPhipps/Powershell/blob/master/Get-FlatYAML.ps1) (Or, if using PowerBI, from https://github.com/TonyPhipps/tech-notes/blob/main/Products/powerbi/sigma.md) (Command: .\Get-FlatYAML.ps1 -InputDir “d:\Github\sigma\rules” -Outputfile “d:\sigma.csv” -IgnoreFields detection, related)

NIST SP-00-53

(From https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)

NIST to MITRE Techniques

(From https://center-for-threat-informed-defense.github.io/mappings-explorer/external/nist/)