Refactor the `risk` property of `detection_abstract` to handle observable/risk/threat mappings more transparently
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
Research direction
Locate the detection_abstract implementation and SES_OBSERVABLE_TYPE_MAPPING, then review how observable types, roles, risks, and threats are currently connected. Read PR #234 for the related user/Attacker behavior. Done means the mapping is transparent and user observables resolve to the intended user threat type rather than an unintended risk or other type.
Written by the indexing model from the issue text.
Description
- The mappings between risk types and observable types/roles is complicated, confusing, and prone to logical errors and edge cases
- We should refactor it to be a transparent mapping between observable types (as in
SES_OBSERVABLE_TYPE_MAPPING) and risk/threat types - For example, we have users as
Attackersin many detections- Currently, these get mapped to risks instead of threats unintentionally
- Lou's PR (#234) will address this, but even then, user threat object will get the type
otherinstead of user
- Dominant language
- Python
- Stars
- 139
- Forks
- 51
- Avg merge
- 1h 16m
- Merged PRs (30d)
- 3
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from splunk/contentctl
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 45/100
splunk/contentctl#468 · 1 comment ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 38/100
splunk/contentctl#461 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 48/100
splunk/contentctl#452 ·
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 35/100
splunk/contentctl#464 · 3 comments ·
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 35/100
splunk/contentctl#451 ·
All issues in splunk/contentctl
Similar issues
-
New InternshipOpennew_internship
Difficulty 1/5 Under an hour Newbie friendliness 70/100
-
[BUG] Reports tab: "Unban" button tooltip shows raw `{{ip}}` placeholder instead of the IP addressOpenbug javascript ui
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
bunkerity/bunkerweb#4001 · 1 comment ·
Maintainers usually reply within 1 day
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 92/100
PedestrianDynamics/pyFDS-Evac#476 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
google/differential-privacy#516 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
adobe-fonts/source-serif#153 ·