Skip to main content

Enterprise-Only Content Types

Additional content types available under Enterprise

S
Written by Sergey Bayrachny

In this article:

In addition to Sigma Rules that come as Alerts or Queries, users under an Enterprise plan can access other types of content on the SOC Prime Platform.

Content Pack


Content packs are ad-hoc sets of SOC content, scripts, lists and other items intended to solve a specific task, for example detect a particular MITRE ATT&CK tactic, CVE, or APT group, have a security framework in place to make SOC more effective, or implement specific security checks. Content packs are created with SIEM-native tools and exported as archives.

You can download the archive, import it into your SIEM and get going in no time using a dedicated Guide.

Each tab on the Content Pack page contains information specific to the security tool the Pack is created for.

Content Pack page typically contains the following:

Name

Description

Description

Short overview of the purpose and functionality

Dependencies & Recommendation

Required technology, versions, and other important prerequisites

Log Source Requirements

Log sources you need to use this content item

Guide

Instructions on installation and customization

Media

Visual confirmation that the detection is actionable for a certain security technology

MITRE ATT&CK parameters

Tactics, techniques, or sub-techniques, Tools, and Actors according to the MITRE ATT&CK methodology

Click an element to open its MITRE ATT&CK info page

Tags

Supplemental information about the content

Content rating and reviews

Rating and reviews provided by Platform users

The page also shows other useful information, such as version number, release notes (if there are any), compatibility details, and the hash verifying that the code is unique. Make sure to check this information before downloading and deploying the content item.

Premium App


A limited number of specialized applications such as SOC Workflow, Predictive Maintenance Dashboards, Predictive Maintenance Notifications, ECS Premium Log Source Pack, Watcher Management Dashboard, and Anomali ThreatStream Integration.

Premium Apps are not covered by any SOC Prime Platform subscription. To get one of them, send a request on the app page.

Premium app page typically contains the following:

Name

Description

Description

Short overview of the purpose and functionality

Dependencies & Recommendation

Required technology and other important prerequisites

Log Source Requirements

Log sources you need to use this content item

Guide

Instructions on installation and customization

Media

Visual confirmation that the detection is actionable for a certain security technology

MITRE ATT&CK parameters

Tactics, techniques, or sub-techniques, Tools, and Actors according to the MITRE ATT&CK methodology

Tags

Supplemental information about the content

Content reviews

Reviews provided by Platform users

The page also shows other useful information, such as version number, release notes (if there are any), compatibility details, and the hash verifying that the code is unique. Make sure to check this information before downloading and deploying the content item.

Did this answer your question?