Model Mapping Pages
Our model defines five levels of analytic robustness and three columns of event robustness. (See: Definitions) This section goes into deeper detail about how the levels and columns are defined and how to map observables onto our model.
Levels: Analytic Robustness Categories
There are five levels that represent how difficult it is for an adversary to evade an observable.
Columns: Host-Based Event Robustness Columns
There are three columns that represent where event data originates within the OS.
Columns: Network Traffic Robustness Columns
There are two columns that represent visibility into network traffic.
For a quick search of an observable, please utilize the observables page.