In this article: |
In addition to Sigma Rules that come as Alerts or Queries, users under an Enterprise plan can access other types of content on the SOC Prime Platform.
Content Pack
Content packs are ad-hoc sets of SOC content, scripts, lists and other items intended to solve a specific task, for example detect a particular MITRE ATT&CK tactic, CVE, or APT group, have a security framework in place to make SOC more effective, or implement specific security checks. Content packs are created with SIEM-native tools and exported as archives.
You can download the archive, import it into your SIEM and get going in no time using a dedicated Guide.
Each tab on the Content Pack page contains information specific to the security tool the Pack is created for.
Content Pack page typically contains the following:
Name | Description |
Description | Short overview of the purpose and functionality |
Dependencies & Recommendation | Required technology, versions, and other important prerequisites |
Log Source Requirements | Log sources you need to use this content item |
Guide | Instructions on installation and customization |
Media | Visual confirmation that the detection is actionable for a certain security technology |
MITRE ATT&CK parameters | Tactics, techniques, or sub-techniques, Tools, and Actors according to the MITRE ATT&CK methodology Click an element to open its MITRE ATT&CK info page |
Tags | Supplemental information about the content |
Content rating and reviews | Rating and reviews provided by Platform users |
The page also shows other useful information, such as version number, release notes (if there are any), compatibility details, and the hash verifying that the code is unique. Make sure to check this information before downloading and deploying the content item.
Premium App
A limited number of specialized applications such as SOC Workflow, Predictive Maintenance Dashboards, Predictive Maintenance Notifications, ECS Premium Log Source Pack, Watcher Management Dashboard, and Anomali ThreatStream Integration.
Premium Apps are not covered by any SOC Prime Platform subscription. To get one of them, send a request on the app page.
Premium app page typically contains the following:
Name | Description |
Description | Short overview of the purpose and functionality |
Dependencies & Recommendation | Required technology and other important prerequisites |
Log Source Requirements | Log sources you need to use this content item |
Guide | Instructions on installation and customization |
Media | Visual confirmation that the detection is actionable for a certain security technology |
MITRE ATT&CK parameters | Tactics, techniques, or sub-techniques, Tools, and Actors according to the MITRE ATT&CK methodology |
Tags | Supplemental information about the content |
Content reviews | Reviews provided by Platform users |
The page also shows other useful information, such as version number, release notes (if there are any), compatibility details, and the hash verifying that the code is unique. Make sure to check this information before downloading and deploying the content item.
