Model Mapping Pages

Our model defines five levels of analytic robustness and three columns of event robustness. (See: Definitions) This section goes into deeper detail about how the levels and columns are defined and how to map observables onto our model.

Levels: Analytic Robustness Categories

There are five levels that represent how difficult it is for an adversary to evade an observable.

Columns: Host-Based Event Robustness Columns

There are three columns that represent where event data originates within the OS.

Columns: Network Traffic Robustness Columns

There are two columns that represent visibility into network traffic.

For a quick search of an observable, please utilize the observables page.