Skip to content

Commit

Permalink
Merge pull request #172 from mitre-attack/dependabot/bundler/docs/nok…
Browse files Browse the repository at this point in the history
…ogiri-1.14.3

Bump nokogiri from 1.13.10 to 1.14.3 in /docs
  • Loading branch information
alexiacrumpton authored Jan 9, 2024
2 parents 93dc5e8 + 49b8450 commit 83bf2b0
Show file tree
Hide file tree
Showing 11 changed files with 492 additions and 492 deletions.
6 changes: 3 additions & 3 deletions docs/Gemfile.lock
Original file line number Diff line number Diff line change
Expand Up @@ -213,14 +213,14 @@ GEM
rb-inotify (~> 0.9, >= 0.9.7)
ruby_dep (~> 1.2)
mercenary (0.3.6)
mini_portile2 (2.8.0)
mini_portile2 (2.8.1)
minima (2.5.0)
jekyll (~> 3.5)
jekyll-feed (~> 0.9)
jekyll-seo-tag (~> 2.1)
minitest (5.11.3)
multipart-post (2.1.1)
nokogiri (1.13.10)
nokogiri (1.14.3)
mini_portile2 (~> 2.8.0)
racc (~> 1.4)
octokit (4.21.0)
Expand All @@ -229,7 +229,7 @@ GEM
pathutil (0.16.2)
forwardable-extended (~> 2.6)
public_suffix (2.0.5)
racc (1.6.1)
racc (1.6.2)
rb-fsevent (0.11.0)
rb-inotify (0.10.1)
ffi (~> 1.0)
Expand Down
82 changes: 41 additions & 41 deletions docs/analytics/by_technique/index.md

Large diffs are not rendered by default.

584 changes: 292 additions & 292 deletions docs/car_attack/car_attack.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion docs/data/analytics.json

Large diffs are not rendered by default.

30 changes: 15 additions & 15 deletions docs/sensors/auditd_2.8.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,21 +15,6 @@ auditd is the userspace component to the Linux Auditing System. It's responsible

## Data Model Coverage

### [process](../data_model/process)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| || | | || || | | | ||||| | | | | | | | ||
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [driver](../data_model/driver)

| | `base_address` | `fqdn` | `hostname` | `image_path` | `md5_hash` | `module_name` | `pid` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` |
|---|---|---|---|---|---|---|---|---|---|---|
| `load` | | | |||| ||| | |
| `unload` | | | | | | | | | | | |

### [flow](../data_model/flow)

| | `application_protocol` | `content` | `dest_fqdn` | `dest_hostname` | `dest_ip` | `dest_port` | `end_time` | `exe` | `fqdn` | `hostname` | `image_path` | `in_bytes` | `network_direction` | `out_bytes` | `packet_count` | `pid` | `ppid` | `proto_info` | `src_fqdn` | `src_hostname` | `src_ip` | `src_port` | `start_time` | `tcp_flags` | `transport_protocol` | `uid` | `user` |
Expand All @@ -50,6 +35,21 @@ auditd is the userspace component to the Linux Auditing System. It's responsible
| `timestomp` | | || ||| | | | || || | | | ||| ||| | | ||
| `write` | | || ||| | | | || || | | | ||| ||| | | ||

### [process](../data_model/process)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| || | | || || | | | ||||| | | | | | | | ||
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [driver](../data_model/driver)

| | `base_address` | `fqdn` | `hostname` | `image_path` | `md5_hash` | `module_name` | `pid` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` |
|---|---|---|---|---|---|---|---|---|---|---|
| `load` | | | |||| ||| | |
| `unload` | | | | | | | | | | | |




Expand Down
34 changes: 17 additions & 17 deletions docs/sensors/autoruns_13.98.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,14 +14,17 @@ Autoruns reports Explorer shell extensions, toolbars, browser helper objects, Wi

## Data Model Coverage

### [registry](../data_model/registry)
### [file](../data_model/file)

| | `data` | `fqdn` | `hive` | `hostname` | `image_path` | `key` | `new_content` | `pid` | `type` | `user` | `value` |
|---|---|---|---|---|---|---|---|---|---|---|
| `add` ||||| || | || ||
| `key_edit` ||||| ||| || ||
| `remove` | | | | | | | | | | | |
| `value_edit` ||||| ||| || ||
| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` || || |||| | ||| || | | | | | | ||| || | |
| `delete` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `modify` || || |||| | ||| || | | | | | | ||| || | |
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `write` | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [service](../data_model/service)

Expand All @@ -33,17 +36,14 @@ Autoruns reports Explorer shell extensions, toolbars, browser helper objects, Wi
| `start` | | | | | | | | | | |
| `stop` | | | | | | | | | | |

### [file](../data_model/file)
### [registry](../data_model/registry)

| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` || || |||| | ||| || | | | | | | ||| || | |
| `delete` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `modify` || || |||| | ||| || | | | | | | ||| || | |
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `write` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | `data` | `fqdn` | `hive` | `hostname` | `image_path` | `key` | `new_content` | `pid` | `type` | `user` | `value` |
|---|---|---|---|---|---|---|---|---|---|---|
| `add` ||||| || | || ||
| `key_edit` ||||| ||| || ||
| `remove` | | | | | | | | | | | |
| `value_edit` ||||| ||| || ||



Expand Down
30 changes: 15 additions & 15 deletions docs/sensors/osquery_4.1.2.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,21 +14,6 @@ osquery exposes an operating system as a high-performance relational database. T

## Data Model Coverage

### [process](../data_model/process)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| || | | || || | | | ||||| | | | | | | | ||
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [driver](../data_model/driver)

| | `base_address` | `fqdn` | `hostname` | `image_path` | `md5_hash` | `module_name` | `pid` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` |
|---|---|---|---|---|---|---|---|---|---|---|
| `load` | | | |||| ||| | |
| `unload` | | | | | | | | | | | |

### [flow](../data_model/flow)

| | `application_protocol` | `content` | `dest_fqdn` | `dest_hostname` | `dest_ip` | `dest_port` | `end_time` | `exe` | `fqdn` | `hostname` | `image_path` | `in_bytes` | `network_direction` | `out_bytes` | `packet_count` | `pid` | `ppid` | `proto_info` | `src_fqdn` | `src_hostname` | `src_ip` | `src_port` | `start_time` | `tcp_flags` | `transport_protocol` | `uid` | `user` |
Expand All @@ -49,6 +34,21 @@ osquery exposes an operating system as a high-performance relational database. T
| `timestomp` | | || ||| | | | || || | | | ||| ||| | | ||
| `write` | | || ||| | | | || || | | | ||| ||| | | ||

### [process](../data_model/process)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| || | | || || | | | ||||| | | | | | | | ||
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [driver](../data_model/driver)

| | `base_address` | `fqdn` | `hostname` | `image_path` | `md5_hash` | `module_name` | `pid` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` |
|---|---|---|---|---|---|---|---|---|---|---|
| `load` | | | |||| ||| | |
| `unload` | | | | | | | | | | | |




Expand Down
30 changes: 15 additions & 15 deletions docs/sensors/osquery_4.6.0.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,21 +14,6 @@ osquery exposes an operating system as a high-performance relational database. T

## Data Model Coverage

### [process](../data_model/process)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||||| | | || || | | | ||||| | | | | | | || |
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [driver](../data_model/driver)

| | `base_address` | `fqdn` | `hostname` | `image_path` | `md5_hash` | `module_name` | `pid` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` |
|---|---|---|---|---|---|---|---|---|---|---|
| `load` | | | |||| ||| | |
| `unload` | | | | | | | | | | | |

### [flow](../data_model/flow)

| | `application_protocol` | `content` | `dest_fqdn` | `dest_hostname` | `dest_ip` | `dest_port` | `end_time` | `exe` | `fqdn` | `hostname` | `image_path` | `in_bytes` | `network_direction` | `out_bytes` | `packet_count` | `pid` | `ppid` | `proto_info` | `src_fqdn` | `src_hostname` | `src_ip` | `src_port` | `start_time` | `tcp_flags` | `transport_protocol` | `uid` | `user` |
Expand All @@ -49,6 +34,21 @@ osquery exposes an operating system as a high-performance relational database. T
| `timestomp` | | || ||| | | | || || || | ||| ||| | | ||
| `write` | | || ||| | | | || || || | ||| ||| | | ||

### [process](../data_model/process)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||||| | | || || | | | ||||| | | | | | | || |
| `terminate` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [driver](../data_model/driver)

| | `base_address` | `fqdn` | `hostname` | `image_path` | `md5_hash` | `module_name` | `pid` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` |
|---|---|---|---|---|---|---|---|---|---|---|
| `load` | | | |||| ||| | |
| `unload` | | | | | | | | | | | |




Expand Down
62 changes: 31 additions & 31 deletions docs/sensors/sysmon_10.4.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,13 +14,25 @@ Sysmon is a freely available program from Microsoft that is provided as part of

## Data Model Coverage

### [process](../data_model/process)
### [flow](../data_model/flow)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| | || | ||||| | |||||| | | | | | | | ||
| `terminate` | | | | | | || | || | | | | | || | | | | | | | | | | | |
| | `application_protocol` | `content` | `dest_fqdn` | `dest_hostname` | `dest_ip` | `dest_port` | `end_time` | `exe` | `fqdn` | `hostname` | `image_path` | `in_bytes` | `network_direction` | `out_bytes` | `packet_count` | `pid` | `ppid` | `proto_info` | `src_fqdn` | `src_hostname` | `src_ip` | `src_port` | `start_time` | `tcp_flags` | `transport_protocol` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `end` | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `message` | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `start` | | | |||| | | | || | | | || | | ||||| | | ||

### [file](../data_model/file)

| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | || || || | | || | | | | | || | | | | | | | |
| `delete` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | || || || | | || | | | | | || || | | | | | |
| `write` | | | | | | | | | | | | | | | | | | | | | | | | | | |

### [registry](../data_model/registry)

Expand All @@ -31,20 +43,21 @@ Sysmon is a freely available program from Microsoft that is provided as part of
| `remove` | ||| ||| || | ||
| `value_edit` | | | | | | | | | | | |

### [driver](../data_model/driver)

| | `base_address` | `fqdn` | `hostname` | `image_path` | `md5_hash` | `module_name` | `pid` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` |
|---|---|---|---|---|---|---|---|---|---|---|
| `load` | || ||| | ||| ||
| `unload` | | | | | | | | | | | |

### [module](../data_model/module)

| | `base_address` | `fqdn` | `hostname` | `image_path` | `md5_hash` | `module_name` | `module_path` | `pid` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `tid` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `load` | || ||| ||||| || |
| `unload` | | | | | | | | | | | | | |

### [process](../data_model/process)

| | `access_level` | `call_trace` | `command_line` | `current_working_directory` | `env_vars` | `exe` | `fqdn` | `guid` | `hostname` | `image_path` | `integrity_level` | `md5_hash` | `parent_command_line` | `parent_exe` | `parent_guid` | `parent_image_path` | `pid` | `ppid` | `sha1_hash` | `sha256_hash` | `sid` | `signature_valid` | `signer` | `target_address` | `target_guid` | `target_name` | `target_pid` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `access` | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | ||| | || | ||||| | |||||| | | | | | | | ||
| `terminate` | | | | | | || | || | | | | | || | | | | | | | | | | | |

### [thread](../data_model/thread)

| | `hostname` | `src_pid` | `src_tid` | `stack_base` | `stack_limit` | `start_address` | `start_function` | `start_module` | `start_module_name` | `tgt_pid` | `tgt_tid` | `uid` | `user` | `user_stack_base` | `user_stack_limit` |
Expand All @@ -54,25 +67,12 @@ Sysmon is a freely available program from Microsoft that is provided as part of
| `suspend` | | | | | | | | | | | | | | | |
| `terminate` | | | | | | | | | | | | | | | |

### [flow](../data_model/flow)

| | `application_protocol` | `content` | `dest_fqdn` | `dest_hostname` | `dest_ip` | `dest_port` | `end_time` | `exe` | `fqdn` | `hostname` | `image_path` | `in_bytes` | `network_direction` | `out_bytes` | `packet_count` | `pid` | `ppid` | `proto_info` | `src_fqdn` | `src_hostname` | `src_ip` | `src_port` | `start_time` | `tcp_flags` | `transport_protocol` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `end` | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `message` | | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `start` | | | |||| | | | || | | | || | | ||||| | | ||

### [file](../data_model/file)
### [driver](../data_model/driver)

| | `company` | `content` | `creation_time` | `extension` | `file_name` | `file_path` | `fqdn` | `gid` | `group` | `hostname` | `image_path` | `link_target` | `md5_hash` | `mime_type` | `mode` | `owner` | `owner_uid` | `pid` | `ppid` | `previous_creation_time` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` | `uid` | `user` |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| `acl_modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `create` | | || || || | | || | | | | | || | | | | | | | |
| `delete` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `modify` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `read` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| `timestomp` | | || || || | | || | | | | | || || | | | | | |
| `write` | | | | | | | | | | | | | | | | | | | | | | | | | | |
| | `base_address` | `fqdn` | `hostname` | `image_path` | `md5_hash` | `module_name` | `pid` | `sha1_hash` | `sha256_hash` | `signature_valid` | `signer` |
|---|---|---|---|---|---|---|---|---|---|---|
| `load` | || ||| | ||| ||
| `unload` | | | | | | | | | | | |



Expand Down
Loading

0 comments on commit 83bf2b0

Please sign in to comment.