prowler-cloud/prowler

In the prowler ocsf.json report, the Finding_info entity is missing Analytic, and Attack field

已关闭

#7,176 创建于 2025年3月11日

 (3 条评论) (1 个反应) (0 位负责人)Python (1,322 个派生)batch import
feature-requesthelp wantedoutput/ocsf

仓库指标

星标
 (8,957 个星标)
PR 合并指标
 (平均合并 9天 17小时) (30 天内合并 314 个 PR)

描述

New feature motivation

In the OCSF schema, finding info entity can have following fields https://schema.ocsf.io/1.4.0/objects/finding_info?extensions=

Among them, Analytic can have following fields https://schema.ocsf.io/1.4.0/objects/analytic?extensions=

Attack which will have mitre attack descriptions, can have following field https://schema.ocsf.io/1.4.0/objects/attack?extensions=

It would be great if you can add these details in the report.

Solution Proposed

Currently wazuh agent provide us details about analytic and attack fields. But wazuh does not follow OCSF schema, so you wont find it with analytic and attack name.

A sample wazuh alert is attached. You can follow this link to convert wazuh fields to ocsf field related to attack and analytic

https://documentation.wazuh.com/current/integrations-guide/amazon-security-lake/index.html

wazuh_alerts_2025-03-07.json

Describe alternatives you've considered

N/A

Additional context

No response

贡献者指南