DAC

Chapter 3

Detection as Code

Working with the Detection as Code

Subsections of DAC

Templates

Template Purpose

ODEF provides two templates for documenting detections — yaml and markdown. Each for different purpose:

  • Yaml is used due to its data serialization and wide programming language compatibility. It is used for automation and integrations with other systems. It stores components like the queries, baseline, schedule and others. It is a stepping stone for Detection-as-Code capability.

  • Markdown is used for detection documentation due to its readability and simplicity. Especially helpful for knowledge sharing when used in conjunction with platforms like GitHub. The purpose of the file is to house all details related to the detection. Check the Knowledge Management section for additional information.

The yaml file

Yaml file purpose

status: "{{ status }}"
created_date: "{{ created_date }}"
last_updated_date: 
name: "{{ detection_name }}"
query: "{{ query }}"
author: "{{ detection_author }}"
schedule: "{{ schedule }}"
baseline: "{{ baseline }}"
visualization: "{{ visualization }}"
event_limit: 0
data_source: "{{ data_source }}"
data_location: "{{ data_location }}"
tactic: "{{ tactic }}"
mitre_id: "{{ mitre_id }}"
mitre_url: "{{ mitre_url }}"
incident:
  severity: "numeric, 0-unknown, 0.5 - informational, 1-low,2-medium,3-high,4-critical"
  type: 'Security Incident'
  name: 'string, name of the incident' 
  description: 'inc descr: This detection is monitoring for changes in any of X'
  sla: 'integer - number of minutes added to incident create time(incident sla). example sla: 1440 this means 24h sla'