Document toolboxDocument toolbox

Security Operations Entities Mapping

Entities mapping

This is the specification of common criteria to apply where possible in alert creation for each technology and union table.

The specification includes:

  • Description about the table in use and how can it be used to create alerts.

  • SecOps entities.

  • Alert template to use.

There are various SecOps entities and their union tables:

Â