{ "namespace": "coa", "description": "Course of action taken within organization to discover, detect, deny, disrupt, degrade, deceive and/or destroy an attack.", "version": 2, "predicates": [ { "value": "discover", "expanded": "Search historical data for an indicator.", "uuid": "22037887-5187-5e7a-8549-5c2f19220c2c" }, { "value": "detect", "expanded": "Set up a detection rule for an indicator for future alerting.", "uuid": "511cd50f-e518-5de6-ad24-e0fa243994d3" }, { "value": "deny", "expanded": "Prevent an event from taking place.", "uuid": "e28b6eda-136b-58e8-b95d-0494c8c66074" }, { "value": "disrupt", "expanded": "Make an event fail when it is taking place.", "uuid": "caa28c35-3176-5ccd-b9f5-fc5b3ef2ff7e" }, { "value": "degrade", "expanded": "Slow down attacker activity; reduce attacker efficiency.", "uuid": "17c79d7d-187e-51eb-b92b-2dec468264c0" }, { "value": "deceive", "expanded": "Pretend only that an action was successful or provide misinformation to the attacker.", "uuid": "7124ed66-e257-5aea-b5dd-ffbd3b9fdb5b" }, { "value": "destroy", "expanded": "Offensive action against the attacker.", "uuid": "32c849f1-01f6-55b6-b72b-93497c21b887" } ], "values": [ { "predicate": "discover", "entry": [ { "value": "proxy", "expanded": "Searched historical proxy logs.", "colour": "#005065", "uuid": "6fbed04d-0676-5579-849d-755054fabfeb" }, { "value": "ids", "expanded": "Searched historical IDS logs.", "colour": "#00586f", "uuid": "f377cf6d-ffed-5d7a-9ca8-b66f7ad0df57" }, { "value": "firewall", "expanded": "Searched historical firewall logs.", "colour": "#005f78", "uuid": "9527f641-9e2c-5366-a6d4-6a161f6dc1b8" }, { "value": "pcap", "expanded": "Discovered in packet-capture logs", "colour": "#006681", "uuid": "17864f3c-76aa-522f-9450-b733887fb02e" }, { "value": "remote-access", "expanded": "Searched historical remote access logs.", "colour": "#006e8b", "uuid": "6acbd5d1-c050-56a2-880f-77dfc2461bbe" }, { "value": "authentication", "expanded": "Searched historical authentication logs.", "colour": "#007594", "uuid": "adf7f5d9-ab39-5572-839d-78e928c36f58" }, { "value": "honeypot", "expanded": "Searched historical honeypot data.", "colour": "#007c9d", "uuid": "3715a453-f35a-5319-8f58-fbd27ea03179" }, { "value": "syslog", "expanded": "Searched historical system logs.", "colour": "#0084a6", "uuid": "fbd57320-bf43-5b32-a225-c88def44ebea" }, { "value": "web", "expanded": "Searched historical WAF and web application logs.", "colour": "#008bb0", "uuid": "c67098c5-63f8-5ba8-a817-1eec2ac13aec" }, { "value": "database", "expanded": "Searched historcial database logs.", "colour": "#0092b9", "uuid": "06079062-3fe1-5d59-aa70-c9240223cc45" }, { "value": "mail", "expanded": "Searched historical mail logs.", "colour": "#009ac2", "uuid": "c1f57e25-09ab-5b7b-adff-96951d854746" }, { "value": "antivirus", "expanded": "Searched historical antivirus alerts.", "colour": "#00a1cb", "uuid": "360408cd-56f1-5d47-9b1d-3f04f8d7a267" }, { "value": "malware-collection", "expanded": "Retro hunted in a malware collection.", "colour": "#00a8d5", "uuid": "38eed735-4099-5488-ba54-3308ed17bd42" }, { "value": "other", "expanded": "Searched other historical data.", "colour": "#00b0de", "uuid": "4375b754-6e20-505c-a8a1-b513b692bb20" }, { "value": "unspecified", "expanded": "Unspecified information.", "colour": "#00b7e7", "uuid": "b7d08f95-2582-58a9-af99-08a60be7dfb4" } ] }, { "predicate": "detect", "entry": [ { "value": "proxy", "expanded": "Detect by Proxy infrastructure", "colour": "#0abdeb", "uuid": "a41b2529-74fd-5618-94b2-673c189fcab3" }, { "value": "nids", "expanded": "Detect by Network Intrusion detection system.", "colour": "#13c5f4", "uuid": "58711d80-8846-5686-81e3-9b46c920523d" }, { "value": "hids", "expanded": "Detect by Host Intrusion detection system.", "colour": "#24c9f5", "uuid": "ff994534-edeb-55cf-b95e-32c96bb3a319" }, { "value": "other", "expanded": "Detect by other tools.", "colour": "#35cef5", "uuid": "d227bcf3-4f8b-5d82-99c4-72e39a0cf30d" }, { "value": "syslog", "expanded": "Detect in system logs.", "colour": "#45d2f6", "uuid": "6a05770f-0901-5efc-b71a-c78959864b11" }, { "value": "firewall", "expanded": "Detect by firewall.", "colour": "#56d6f7", "uuid": "b7128eaf-cd16-59ef-9988-cf02b895f4cc" }, { "value": "email", "expanded": "Detect by MTA.", "colour": "#67daf8", "uuid": "66a3f50b-deda-5293-8aa1-75fa99a0a81e" }, { "value": "web", "expanded": "Detect by web infrastructure including WAF.", "colour": "#78def8", "uuid": "be4feef9-6985-5db2-bc22-e15b98c214c8" }, { "value": "database", "expanded": "Detect in database.", "colour": "#89e2f9", "uuid": "fb848e16-6fff-56a6-9744-92fe7f44c0e1" }, { "value": "remote-access", "expanded": "Detect in remote-access logs.", "colour": "#9ae6fa", "uuid": "6f42385a-542b-5d04-9e38-fba51aa872b1" }, { "value": "malware-collection", "expanded": "Detect in malware-collection.", "colour": "#aaeafb", "uuid": "6150ae59-634e-508e-ab8f-d4aae2b5e52c" }, { "value": "antivirus", "expanded": "Detect with antivirus.", "colour": "#bbeefb", "uuid": "ce2b2b58-7f12-5dc2-ab23-9f1ef32fc05a" }, { "value": "unspecified", "expanded": "Unspecified information.", "colour": "#ccf2fc", "uuid": "d537d4af-d1ce-5ccf-a4ca-6847eb506816" } ] }, { "predicate": "deny", "entry": [ { "value": "proxy", "expanded": "Implemented a proxy filter.", "colour": "#f09105", "uuid": "531050c0-a18e-5cff-bdb7-cf624c2b81e9" }, { "value": "firewall", "expanded": "Implemented a block rule on a firewall.", "colour": "#f99a0e", "uuid": "1175bb2b-617c-5ede-a5e7-e7732e0fa586" }, { "value": "waf", "expanded": "Implemented a block rule on a web application firewall.", "colour": "#f9a11f", "uuid": "2b2fad10-e363-5492-9218-b33ea33b4d8e" }, { "value": "email", "expanded": "Implemented a filter on a mail transfer agent.", "colour": "#faa830", "uuid": "e3c1afc2-bfef-5e90-8b75-3f8366c64de6" }, { "value": "chroot", "expanded": "Implemented a chroot jail.", "colour": "#faaf41", "uuid": "d471a6ff-f5ec-5103-a18c-8651d8b5bab6" }, { "value": "remote-access", "expanded": "Blocked an account for remote access.", "colour": "#fbb653", "uuid": "da6c9487-fb56-568f-bed6-22f6cf1abbee" }, { "value": "other", "expanded": "Denied an action by other means.", "colour": "#fbbe64", "uuid": "d7a31273-6b7e-566b-87c0-5bd15d63804b" }, { "value": "unspecified", "expanded": "Unspecified information.", "colour": "#fbc575", "uuid": "63154b82-81a0-5796-8896-132d85889acb" } ] }, { "predicate": "disrupt", "entry": [ { "value": "nips", "expanded": "Implemented a rule on a network IPS.", "colour": "#660389", "uuid": "91442d81-a954-59a1-9cdc-216f5b2ab327" }, { "value": "hips", "expanded": "Implemented a rule on a host-based IPS.", "colour": "#73039a", "uuid": "1d7a27cf-6b6e-510a-935f-c77ea676f213" }, { "value": "other", "expanded": "Disrupted an action by other means.", "colour": "#8003ab", "uuid": "68930046-de71-53ac-a4fa-54ecc939314c" }, { "value": "email", "expanded": "Quarantined an email.", "colour": "#8d04bd", "uuid": "86a6b9c6-3671-5236-9f71-8746b5499b1f" }, { "value": "memory-protection", "expanded": "Implemented memory protection like DEP and/or ASLR.", "colour": "#9a04ce", "uuid": "879b2ba6-0a64-5829-b5d4-968b9944c1c9" }, { "value": "sandboxing", "expanded": "Exploded in a sandbox.", "colour": "#a605df", "uuid": "0014b6dd-cd6b-5930-ab05-0b0db3c17072" }, { "value": "antivirus", "expanded": "Activated an antivirus signature.", "colour": "#b305f0", "uuid": "dc563d22-64dc-5d29-a540-440fb2c5eb26" }, { "value": "unspecified", "expanded": "Unspecified information.", "colour": "#bc0ef9", "uuid": "35e66e63-6b93-566f-b5ff-cd9843dfae06" } ] }, { "predicate": "degrade", "entry": [ { "value": "bandwidth", "expanded": "Throttled the bandwidth.", "colour": "#0421ce", "uuid": "9190b0a8-b4f3-5346-a2e7-0c4390869ecd" }, { "value": "tarpit", "expanded": "Implement a network tarpit.", "colour": "#0523df", "uuid": "d1bbe87a-97d0-5013-94dc-0f9c832c238c" }, { "value": "other", "expanded": "Degraded an action by other means.", "colour": "#0526f0", "uuid": "e5d2eec6-f401-59b4-b3d8-0d0dfa1e9dda" }, { "value": "email", "expanded": "Queued an email.", "colour": "#0e2ff9", "uuid": "1ea8e470-470f-5b8a-b69a-3be1e68347fa" }, { "value": "unspecified", "expanded": "Unspecified information.", "colour": "#1f3ef9", "uuid": "e378a7bc-2018-58d8-a5eb-28115b853035" } ] }, { "predicate": "deceive", "entry": [ { "value": "honeypot", "expanded": "Implemented an interactive honeypot.", "colour": "#0eb274", "uuid": "868f552a-246c-515f-9ed9-e91e8b85df42" }, { "value": "DNS", "expanded": "Implemented DNS redirects, e.g. a response policy zone.", "colour": "#10c37f", "uuid": "516dce83-427a-59d4-a684-ff0073a0fb93" }, { "value": "other", "expanded": "Deceived the attacker with other technology.", "colour": "#11d389", "uuid": "8cb3425d-2bb8-527e-82f3-8701313baedd" }, { "value": "email", "expanded": "Implemented email redirection.", "colour": "#12e394", "uuid": "856ea408-305c-521c-b224-c26161ee9c09" }, { "value": "unspecified", "expanded": "Unspecified information.", "colour": "#1bec9d", "uuid": "a18152cf-bc98-528f-b324-db7469083e19" } ] }, { "predicate": "destroy", "entry": [ { "value": "arrest", "expanded": "Arrested the threat actor.", "colour": "#c33210", "uuid": "72ee0cba-c53c-5560-81ca-696bfd49f016" }, { "value": "seize", "expanded": "Seized attacker infrastructure.", "colour": "#d33611", "uuid": "eaa0e21a-c904-54f7-92fd-134a03ea9913" }, { "value": "physical", "expanded": "Physically destroyed attacker hardware.", "colour": "#e33b12", "uuid": "54dfa69a-8d88-50ac-841f-3305fc8ccd8f" }, { "value": "dos", "expanded": "Performed a denial-of-service attack against attacker infrastructure.", "colour": "#ec441b", "uuid": "1ff756f2-1b69-5af9-81f1-1dc9bf86c86a" }, { "value": "hack-back", "expanded": "Hack back against the threat actor.", "colour": "#ed512b", "uuid": "f7b34af4-482f-5017-8b4a-8ac67fe65a1a" }, { "value": "other", "expanded": "Carried out other offensive actions against the attacker.", "colour": "#ee5e3b", "uuid": "3abd28e1-a627-554c-99c8-092b0955a227" }, { "value": "unspecified", "expanded": "Unspecified information.", "colour": "#f06c4c", "uuid": "85ae52b5-8f4a-5387-8c5b-f00e194ce9cf" } ] } ], "uuid": "53b5eab0-d465-53d0-9dcf-a34a9aa874e8" }