Sign inSign up

mrbl4cyk/atc-api

By mrbl4cyk

•Updated over 6 years ago

Atomic Threat Coverage REST API

Image
0

230

mrbl4cyk/atc-api repository overview

⁠ATC REST API

RESTful API built with Django Rest Framework. This project consumes following Atomic Threat Coverage entities and makes them interactive via HTTP methods:

  • Detection Rules based on Sigma — Generic Signature Format for SIEM Systems
  • Data Needed to be collected to produce detection of specific Threat
  • Logging Policies need to be configured on data source to be able to collect Data Needed
  • Enrichments for specific Data Needed which required for some Detection Rules
  • Response Actions which executed during Incident Response
  • Response Playbooks for reacting on specific threat, constructed from atomic Response Actions

The purpose of this project is to make all the ATC analytics available for 3rd party scripts and any other integrations.

⁠Description

ATC REST API provides you handful of endpoits and filters associated with them for you to query the data. Inserting and updating data on the other hand is restricted only to the authenticated users. List of valid endpoints associated with the supported ATC entities is:

  • /api/v1/atc/detectionrule/
  • /api/v1/atc/dataneeded/
  • /api/v1/atc/loggingpolicy/
  • /api/v1/atc/enrichment/
  • /api/v1/atc/responseaction/
  • /api/v1/atc/responseplaybook/

Some endpoints are not to temper with directly, even though you can view the data. Those endpoints are:

  • /api/v1/atc/category/
  • /api/v1/atc/channel/
  • /api/v1/atc/eventid/
  • /api/v1/atc/logfield/
  • /api/v1/atc/logtype/
  • /api/v1/atc/platform/
  • /api/v1/atc/provider/
  • /api/v1/atc/references/
  • /api/v1/atc/stage/
  • /api/v1/atc/tag/
  • /api/v1/atc/volume/

We have decided that for the statistics purposes you might want to have this available so no restrictions from our side. However, like it was mentioned already, those are and should be considered Read Only data.

On top of that, all of the endpoints support exact id match, for instance: /api/v1/atc/eventid/4688/

Tag summary

Content type

Image

Digest

Size

100 MB

Last updated

over 6 years ago

docker pull mrbl4cyk/atc-api