<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DAC :: ODEF</title><link>https://odef.wiki/dac/index.html</link><description>Chapter 3 Detection as Code Working with the Detection as Code</description><generator>Hugo</generator><language>en-US</language><atom:link href="https://odef.wiki/dac/index.xml" rel="self" type="application/rss+xml"/><item><title>Templates</title><link>https://odef.wiki/dac/odef-templates/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://odef.wiki/dac/odef-templates/index.html</guid><description>Template Purpose ODEF provides two templates for documenting detections — yaml and markdown. Each for different purpose:&#10;Yaml is used due to its data serialization and wide programming language compatibility. It is used for automation and integrations with other systems. It stores components like the queries, baseline, schedule and others. It is a stepping stone for Detection-as-Code capability.</description></item><item><title>The yaml file</title><link>https://odef.wiki/dac/yml-file/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://odef.wiki/dac/yml-file/index.html</guid><description>Yaml file purpose status: "{{ status }}" created_date: "{{ created_date }}" last_updated_date: name: "{{ detection_name }}" query: "{{ query }}" author: "{{ detection_author }}" schedule: "{{ schedule }}" baseline: "{{ baseline }}" visualization: "{{ visualization }}" event_limit: 0 data_source: "{{ data_source }}" data_location: "{{ data_location }}" tactic: "{{ tactic }}" mitre_id: "{{ mitre_id }}" mitre_url: "{{ mitre_url }}" incident: severity: "numeric, 0-unknown, 0.5 - informational, 1-low,2-medium,3-high,4-critical" type: 'Security Incident' name: 'string, name of the incident' description: 'inc descr: This detection is monitoring for changes in any of X' sla: 'integer - number of minutes added to incident create time(incident sla). example sla: 1440 this means 24h sla'</description></item></channel></rss>