Documentation
¶
Index ¶
- func NewHypothesisGenerator(config *types.HypothesisGeneratorConfig, logger *logrus.Logger) (*types.HypothesisGenerator, error)
- type AIAssistantConfig
- type AIHuntingAssistant
- type AIInsights
- type AdvancedThreatHunter
- func (th *AdvancedThreatHunter) ExecuteHunt(ctx context.Context, huntID string) (*ThreatHuntResults, error)
- func (th *AdvancedThreatHunter) GenerateHypothesis(ctx context.Context, request *HypothesisRequest) (*ThreatHypothesis, error)
- func (th *AdvancedThreatHunter) GetActiveHunts() []*ThreatHunt
- func (th *AdvancedThreatHunter) GetActiveInvestigations() []*ThreatInvestigation
- func (th *AdvancedThreatHunter) GetHuntingStats() *ThreatHuntingStats
- func (th *AdvancedThreatHunter) StartInvestigation(ctx context.Context, request *InvestigationRequest) (*ThreatInvestigation, error)
- func (th *AdvancedThreatHunter) StartThreatHunt(ctx context.Context, request *ThreatHuntRequest) (*ThreatHunt, error)
- type AnalyticResults
- type AnomalyDetector
- type AnomalyDetectorConfig
- type AutomationEngine
- type AutomationEngineConfig
- type BehaviorAnalyzer
- type BehaviorAnalyzerConfig
- type CollaborationEngine
- type CollaborationEngineConfig
- type CorrelationEngine
- type CorrelationEngineConfig
- type CorrelationResults
- type HuntAnalytic
- type HuntPhase
- type HuntPhaseResults
- type HuntQuery
- type HuntReport
- type HuntStrategy
- type HuntTechnique
- type HuntingEngine
- type HuntingEngineConfig
- type HuntingWorkflow
- type HuntingWorkflowConfig
- type HypothesisGenerator
- type HypothesisGeneratorConfig
- type HypothesisRequest
- type IndicatorEngine
- type IndicatorEngineConfig
- type IntelligenceEngineConfig
- type IntelligenceResults
- type InvestigationEngine
- type InvestigationEngineConfig
- type InvestigationRequest
- type KnowledgeBaseConfig
- type MLEngineConfig
- type MLHuntingEngine
- type MLResults
- type QueryResults
- type ReportingEngine
- type ReportingEngineConfig
- type TechniqueResults
- type ThreatFinding
- type ThreatHunt
- type ThreatHuntRequest
- type ThreatHuntResults
- type ThreatHuntingConfig
- type ThreatHuntingStats
- type ThreatHypothesis
- type ThreatIntelligenceEngine
- type ThreatInvestigation
- type ThreatKnowledgeBase
- type VisualizationEngine
- type VisualizationEngineConfig
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func NewHypothesisGenerator ¶
func NewHypothesisGenerator(config *types.HypothesisGeneratorConfig, logger *logrus.Logger) (*types.HypothesisGenerator, error)
Types ¶
type AIAssistantConfig ¶
type AIAssistantConfig struct{}
type AIHuntingAssistant ¶
type AIHuntingAssistant struct{}
func NewAIHuntingAssistant ¶
func NewAIHuntingAssistant(config *AIAssistantConfig, logger *logrus.Logger) (*AIHuntingAssistant, error)
func (*AIHuntingAssistant) GenerateInsights ¶
func (aia *AIHuntingAssistant) GenerateInsights(ctx context.Context, hunt *ThreatHunt, results *ThreatHuntResults) (*AIInsights, error)
type AIInsights ¶
type AIInsights struct{}
type AdvancedThreatHunter ¶
type AdvancedThreatHunter struct {
// contains filtered or unexported fields
}
AdvancedThreatHunter - The most sophisticated threat hunting system Revolutionizes proactive threat detection with AI-powered hunting capabilities
func NewAdvancedThreatHunter ¶
func NewAdvancedThreatHunter(config *ThreatHuntingConfig, logger *logrus.Logger) (*AdvancedThreatHunter, error)
NewAdvancedThreatHunter creates a new advanced threat hunting system
func (*AdvancedThreatHunter) ExecuteHunt ¶
func (th *AdvancedThreatHunter) ExecuteHunt(ctx context.Context, huntID string) (*ThreatHuntResults, error)
ExecuteHunt executes the threat hunting process
func (*AdvancedThreatHunter) GenerateHypothesis ¶
func (th *AdvancedThreatHunter) GenerateHypothesis(ctx context.Context, request *HypothesisRequest) (*ThreatHypothesis, error)
GenerateHypothesis generates a threat hunting hypothesis
func (*AdvancedThreatHunter) GetActiveHunts ¶
func (th *AdvancedThreatHunter) GetActiveHunts() []*ThreatHunt
GetActiveHunts returns all active threat hunts
func (*AdvancedThreatHunter) GetActiveInvestigations ¶
func (th *AdvancedThreatHunter) GetActiveInvestigations() []*ThreatInvestigation
GetActiveInvestigations returns all active investigations
func (*AdvancedThreatHunter) GetHuntingStats ¶
func (th *AdvancedThreatHunter) GetHuntingStats() *ThreatHuntingStats
GetHuntingStats returns threat hunting statistics
func (*AdvancedThreatHunter) StartInvestigation ¶
func (th *AdvancedThreatHunter) StartInvestigation(ctx context.Context, request *InvestigationRequest) (*ThreatInvestigation, error)
StartInvestigation initiates a threat investigation
func (*AdvancedThreatHunter) StartThreatHunt ¶
func (th *AdvancedThreatHunter) StartThreatHunt(ctx context.Context, request *ThreatHuntRequest) (*ThreatHunt, error)
StartThreatHunt initiates a new threat hunt
type AnalyticResults ¶
type AnalyticResults struct{}
type AnomalyDetector ¶
type AnomalyDetector struct {
// contains filtered or unexported fields
}
AnomalyDetector identifies anomalous activities
func NewAnomalyDetector ¶
func NewAnomalyDetector(config *AnomalyDetectorConfig, logger *logrus.Logger) (*AnomalyDetector, error)
type AnomalyDetectorConfig ¶
type AnomalyDetectorConfig struct{}
type AutomationEngine ¶
type AutomationEngine struct{}
func NewAutomationEngine ¶
func NewAutomationEngine(config *AutomationEngineConfig, logger *logrus.Logger) (*AutomationEngine, error)
func (*AutomationEngine) StartAutomatedHunt ¶
func (ae *AutomationEngine) StartAutomatedHunt(ctx context.Context, hunt *ThreatHunt) error
type AutomationEngineConfig ¶
type AutomationEngineConfig struct{}
type BehaviorAnalyzer ¶
type BehaviorAnalyzer struct {
// contains filtered or unexported fields
}
BehaviorAnalyzer analyzes behavioral patterns for threats
func NewBehaviorAnalyzer ¶
func NewBehaviorAnalyzer(config *BehaviorAnalyzerConfig, logger *logrus.Logger) (*BehaviorAnalyzer, error)
type CollaborationEngine ¶
type CollaborationEngine struct{}
func NewCollaborationEngine ¶
func NewCollaborationEngine(config *CollaborationEngineConfig, logger *logrus.Logger) (*CollaborationEngine, error)
func (*CollaborationEngine) NotifyHuntCompleted ¶
func (ce *CollaborationEngine) NotifyHuntCompleted(ctx context.Context, hunt *ThreatHunt, results *ThreatHuntResults) error
func (*CollaborationEngine) NotifyHuntStarted ¶
func (ce *CollaborationEngine) NotifyHuntStarted(ctx context.Context, hunt *ThreatHunt) error
type CollaborationEngineConfig ¶
type CollaborationEngineConfig struct{}
type CorrelationEngine ¶
type CorrelationEngine struct {
// contains filtered or unexported fields
}
CorrelationEngine correlates events and indicators
func NewCorrelationEngine ¶
func NewCorrelationEngine(config *CorrelationEngineConfig, logger *logrus.Logger) (*CorrelationEngine, error)
func (*CorrelationEngine) CorrelateFindings ¶
func (ce *CorrelationEngine) CorrelateFindings(ctx context.Context, findings []*ThreatFinding) (*CorrelationResults, error)
type CorrelationEngineConfig ¶
type CorrelationEngineConfig struct{}
type CorrelationResults ¶
type CorrelationResults struct{}
type HuntAnalytic ¶
type HuntAnalytic struct {
Name string `json:"name"`
}
type HuntPhase ¶
type HuntPhase struct {
ID string `json:"id"`
Name string `json:"name"`
Techniques []*HuntTechnique `json:"techniques"`
Queries []*HuntQuery `json:"queries"`
Analytics []*HuntAnalytic `json:"analytics"`
}
type HuntPhaseResults ¶
type HuntPhaseResults struct {
PhaseID string `json:"phase_id"`
PhaseName string `json:"phase_name"`
StartTime time.Time `json:"start_time"`
EndTime time.Time `json:"end_time"`
Duration time.Duration `json:"duration"`
Success bool `json:"success"`
Findings []*ThreatFinding `json:"findings"`
Evidence []*types.Evidence `json:"evidence"`
IOCs []*types.IOC `json:"iocs"`
Techniques []*types.MITRETechnique `json:"techniques"`
}
type HuntReport ¶
type HuntReport struct{}
type HuntStrategy ¶
type HuntStrategy struct {
ID string `json:"id"`
Name string `json:"name"`
Type string `json:"type"`
Methodology string `json:"methodology"`
Framework string `json:"framework"`
Phases []*HuntPhase `json:"phases"`
Techniques []*HuntTechnique `json:"techniques"`
DataSources []*types.DataSource `json:"data_sources"`
Tools []*types.HuntTool `json:"tools"`
Queries []*HuntQuery `json:"queries"`
Analytics []*HuntAnalytic `json:"analytics"`
Playbooks []*types.HuntPlaybook `json:"playbooks"`
Automations []*types.HuntAutomation `json:"automations"`
SuccessMetrics []*types.SuccessMetric `json:"success_metrics"`
KillChainMapping *types.KillChainMapping `json:"kill_chain_mapping"`
TacticsMapping map[string][]string `json:"tactics_mapping"`
AdversaryEmulation *types.AdversaryEmulation `json:"adversary_emulation"`
RedTeamScenarios []*types.RedTeamScenario `json:"red_team_scenarios"`
ThreatIntelligence *types.ThreatIntelligenceReq `json:"threat_intelligence"`
CollaborationModel *types.CollaborationModel `json:"collaboration_model"`
QualityAssurance *types.QualityAssurance `json:"quality_assurance"`
}
HuntStrategy defines hunting approach and methodology
type HuntTechnique ¶
type HuntTechnique struct {
Name string `json:"name"`
}
type HuntingEngine ¶
type HuntingEngine struct {
// contains filtered or unexported fields
}
HuntingEngine orchestrates threat hunting activities
func NewHuntingEngine ¶
func NewHuntingEngine(config *HuntingEngineConfig, logger *logrus.Logger) (*HuntingEngine, error)
func (*HuntingEngine) DetermineStrategy ¶
func (he *HuntingEngine) DetermineStrategy(ctx context.Context, hypothesis *ThreatHypothesis, request *ThreatHuntRequest) (*HuntStrategy, error)
Additional method stubs
type HuntingEngineConfig ¶
type HuntingEngineConfig struct {
Enabled bool `yaml:"enabled"`
StrategiesPath string `yaml:"strategies_path"`
PlaybooksPath string `yaml:"playbooks_path"`
AutoExecute bool `yaml:"auto_execute"`
ParallelExecution bool `yaml:"parallel_execution"`
MaxConcurrentHunts int `yaml:"max_concurrent_hunts"`
DefaultTimeout string `yaml:"default_timeout"`
QualityThreshold float64 `yaml:"quality_threshold"`
}
Placeholder configurations - these would be fully implemented
type HuntingWorkflow ¶
type HuntingWorkflow struct{}
Additional type stubs
func NewHuntingWorkflow ¶
func NewHuntingWorkflow(config *HuntingWorkflowConfig, logger *logrus.Logger) (*HuntingWorkflow, error)
func (*HuntingWorkflow) InitializeWorkflow ¶
func (hw *HuntingWorkflow) InitializeWorkflow(ctx context.Context, hunt *ThreatHunt) (*HuntingWorkflow, error)
type HuntingWorkflowConfig ¶
type HuntingWorkflowConfig struct{}
type HypothesisGenerator ¶
type HypothesisGenerator struct {
// contains filtered or unexported fields
}
HypothesisGenerator generates hunting hypotheses
type HypothesisGeneratorConfig ¶
type HypothesisGeneratorConfig struct{}
type HypothesisRequest ¶
type HypothesisRequest struct {
ThreatType string `json:"threat_type"`
ThreatActors []string `json:"threat_actors"`
Techniques []string `json:"techniques"`
Tactics []string `json:"tactics"`
DataSources []*types.DataSource `json:"data_sources"`
Environment *types.Environment `json:"environment"`
Context string `json:"context"`
Priority string `json:"priority"`
RequestedBy string `json:"requested_by"`
Tags []string `json:"tags"`
}
type IndicatorEngine ¶
type IndicatorEngine struct {
// contains filtered or unexported fields
}
IndicatorEngine manages and analyzes threat indicators
func NewIndicatorEngine ¶
func NewIndicatorEngine(config *IndicatorEngineConfig, logger *logrus.Logger) (*IndicatorEngine, error)
type IndicatorEngineConfig ¶
type IndicatorEngineConfig struct {
Enabled bool `yaml:"enabled"`
IOCFeeds []string `yaml:"ioc_feeds"`
CustomIOCs bool `yaml:"custom_iocs"`
IOCExpiration string `yaml:"ioc_expiration"`
IOCScoring bool `yaml:"ioc_scoring"`
IOCEnrichment bool `yaml:"ioc_enrichment"`
IOCCorrelation bool `yaml:"ioc_correlation"`
}
type IntelligenceEngineConfig ¶
type IntelligenceEngineConfig struct{}
type IntelligenceResults ¶
type IntelligenceResults struct{}
type InvestigationEngine ¶
type InvestigationEngine struct {
// contains filtered or unexported fields
}
InvestigationEngine supports threat investigations
func NewInvestigationEngine ¶
func NewInvestigationEngine(config *InvestigationEngineConfig, logger *logrus.Logger) (*InvestigationEngine, error)
func (*InvestigationEngine) InitializeInvestigation ¶
func (ie *InvestigationEngine) InitializeInvestigation(ctx context.Context, investigation *ThreatInvestigation) error
type InvestigationEngineConfig ¶
type InvestigationEngineConfig struct{}
type InvestigationRequest ¶
type InvestigationRequest struct {
Title string `json:"title"`
Description string `json:"description"`
Type string `json:"type"`
Category string `json:"category"`
Priority string `json:"priority"`
Severity string `json:"severity"`
Investigators []*types.Investigator `json:"investigators"`
LeadInvestigator string `json:"lead_investigator"`
TriggerEvent *types.TriggerEvent `json:"trigger_event"`
InitialFindings []*ThreatFinding `json:"initial_findings"`
Scope *types.InvestigationScope `json:"scope"`
Timeline *types.TimeRange `json:"timeline"`
InitiatedBy string `json:"initiated_by"`
Tags []string `json:"tags"`
Metadata map[string]interface{} `json:"metadata"`
}
type KnowledgeBaseConfig ¶
type KnowledgeBaseConfig struct{}
type MLEngineConfig ¶
type MLEngineConfig struct{}
type MLHuntingEngine ¶
type MLHuntingEngine struct{}
func NewMLHuntingEngine ¶
func NewMLHuntingEngine(config *MLEngineConfig, logger *logrus.Logger) (*MLHuntingEngine, error)
func (*MLHuntingEngine) AnalyzeHuntResults ¶
func (mle *MLHuntingEngine) AnalyzeHuntResults(ctx context.Context, results *ThreatHuntResults) (*MLResults, error)
type QueryResults ¶
type QueryResults struct{}
type ReportingEngine ¶
type ReportingEngine struct{}
func NewReportingEngine ¶
func NewReportingEngine(config *ReportingEngineConfig, logger *logrus.Logger) (*ReportingEngine, error)
func (*ReportingEngine) GenerateHuntReport ¶
func (re *ReportingEngine) GenerateHuntReport(ctx context.Context, hunt *ThreatHunt, results *ThreatHuntResults) (*HuntReport, error)
type ReportingEngineConfig ¶
type ReportingEngineConfig struct{}
type TechniqueResults ¶
type TechniqueResults struct {
Findings []*ThreatFinding `json:"findings"`
Evidence []*types.Evidence `json:"evidence"`
IOCs []*types.IOC `json:"iocs"`
Techniques []*types.MITRETechnique `json:"techniques"`
}
type ThreatFinding ¶
type ThreatFinding struct {
ID string `json:"id"`
Type string `json:"type"`
Category string `json:"category"`
Severity string `json:"severity"`
Confidence float64 `json:"confidence"`
Title string `json:"title"`
Description string `json:"description"`
Summary string `json:"summary"`
ThreatActor *types.ThreatActor `json:"threat_actor,omitempty"`
Campaign *types.ThreatCampaign `json:"campaign,omitempty"`
Techniques []*types.MITRETechnique `json:"techniques"`
Tactics []string `json:"tactics"`
IOCs []*types.IOC `json:"iocs"`
Evidence []*types.Evidence `json:"evidence"`
Timeline *types.FindingTimeline `json:"timeline"`
AffectedAssets []*types.AffectedAsset `json:"affected_assets"`
DataExfiltration *types.DataExfiltration `json:"data_exfiltration,omitempty"`
LateralMovement *types.LateralMovement `json:"lateral_movement,omitempty"`
Persistence *types.Persistence `json:"persistence,omitempty"`
PrivilegeEscalation *types.PrivilegeEscalation `json:"privilege_escalation,omitempty"`
DefenseEvasion *types.DefenseEvasion `json:"defense_evasion,omitempty"`
CommandAndControl *types.CommandAndControl `json:"command_and_control,omitempty"`
Impact *types.ThreatImpact `json:"impact"`
RiskScore float64 `json:"risk_score"`
BusinessImpact *types.BusinessImpact `json:"business_impact"`
Recommendations []*types.Recommendation `json:"recommendations"`
RemediationSteps []*types.RemediationStep `json:"remediation_steps"`
ContainmentActions []*types.ContainmentAction `json:"containment_actions"`
EradicationActions []*types.EradicationAction `json:"eradication_actions"`
RecoveryActions []*types.RecoveryAction `json:"recovery_actions"`
LessonsLearned []string `json:"lessons_learned"`
Attribution *types.Attribution `json:"attribution,omitempty"`
GeographicContext *types.GeographicContext `json:"geographic_context,omitempty"`
IndustryContext *types.IndustryContext `json:"industry_context,omitempty"`
RegulatoryImpact *types.RegulatoryImpact `json:"regulatory_impact,omitempty"`
ForensicArtifacts []*types.ForensicArtifact `json:"forensic_artifacts"`
RelatedFindings []string `json:"related_findings"`
ExternalReferences []*types.ExternalReference `json:"external_references"`
DiscoveredBy string `json:"discovered_by"`
DiscoveredAt time.Time `json:"discovered_at"`
UpdatedAt time.Time `json:"updated_at"`
Status string `json:"status"`
AssignedTo []string `json:"assigned_to"`
Priority string `json:"priority"`
Tags []string `json:"tags"`
Metadata map[string]interface{} `json:"metadata"`
}
ThreatFinding represents a discovered threat
type ThreatHunt ¶
type ThreatHunt struct {
ID string `json:"id"`
Name string `json:"name"`
Description string `json:"description"`
Hypothesis *ThreatHypothesis `json:"hypothesis"`
Strategy *HuntStrategy `json:"strategy"`
Status string `json:"status"`
Priority string `json:"priority"`
Hunters []string `json:"hunters"`
StartTime time.Time `json:"start_time"`
EndTime *time.Time `json:"end_time,omitempty"`
Duration time.Duration `json:"duration"`
Progress float64 `json:"progress"`
Findings []*ThreatFinding `json:"findings"`
Evidence []*types.Evidence `json:"evidence"`
IOCs []*types.IOC `json:"iocs"`
Indicators []*types.ThreatIndicator `json:"indicators"`
Techniques []*types.MITRETechnique `json:"techniques"`
Tactics []string `json:"tactics"`
ActorProfile *types.ThreatActorProfile `json:"actor_profile,omitempty"`
Campaign *types.ThreatCampaign `json:"campaign,omitempty"`
Confidence float64 `json:"confidence"`
RiskScore float64 `json:"risk_score"`
Impact *types.ThreatImpact `json:"impact"`
Recommendations []*types.Recommendation `json:"recommendations"`
Artifacts []*types.HuntArtifact `json:"artifacts"`
Timeline *types.HuntTimeline `json:"timeline"`
Collaborators []*types.Collaborator `json:"collaborators"`
AutomationLevel string `json:"automation_level"`
QualityScore float64 `json:"quality_score"`
LessonsLearned []string `json:"lessons_learned"`
NextSteps []string `json:"next_steps"`
RelatedHunts []string `json:"related_hunts"`
ExternalReferences []*types.ExternalReference `json:"external_references"`
Metadata map[string]interface{} `json:"metadata"`
}
ThreatHunt represents an active threat hunt
type ThreatHuntRequest ¶
type ThreatHuntRequest struct {
Name string `json:"name"`
Description string `json:"description"`
Priority string `json:"priority"`
Hunters []string `json:"hunters"`
Hypothesis *ThreatHypothesis `json:"hypothesis,omitempty"`
Strategy *HuntStrategy `json:"strategy,omitempty"`
DataSources []*types.DataSource `json:"data_sources"`
TimeRange *types.TimeRange `json:"time_range"`
Scope *types.HuntScope `json:"scope"`
AutomationLevel string `json:"automation_level"`
InitiatedBy string `json:"initiated_by"`
Tags []string `json:"tags"`
Metadata map[string]interface{} `json:"metadata"`
}
type ThreatHuntResults ¶
type ThreatHuntResults struct {
HuntID string `json:"hunt_id"`
StartTime time.Time `json:"start_time"`
EndTime time.Time `json:"end_time"`
Duration time.Duration `json:"duration"`
Findings []*ThreatFinding `json:"findings"`
Evidence []*types.Evidence `json:"evidence"`
IOCs []*types.IOC `json:"iocs"`
Techniques []*types.MITRETechnique `json:"techniques"`
CorrelationResults *CorrelationResults `json:"correlation_results,omitempty"`
IntelligenceResults *IntelligenceResults `json:"intelligence_results,omitempty"`
MLResults *MLResults `json:"ml_results,omitempty"`
AIInsights *AIInsights `json:"ai_insights,omitempty"`
Report *HuntReport `json:"report,omitempty"`
Success bool `json:"success"`
QualityScore float64 `json:"quality_score"`
}
type ThreatHuntingConfig ¶
type ThreatHuntingConfig struct {
HuntingEngine *HuntingEngineConfig `yaml:"hunting_engine"`
IndicatorEngine *IndicatorEngineConfig `yaml:"indicator_engine"`
BehaviorAnalyzer *BehaviorAnalyzerConfig `yaml:"behavior_analyzer"`
AnomalyDetector *AnomalyDetectorConfig `yaml:"anomaly_detector"`
CorrelationEngine *CorrelationEngineConfig `yaml:"correlation_engine"`
IntelligenceEngine *IntelligenceEngineConfig `yaml:"intelligence_engine"`
HypothesisGenerator *types.HypothesisGeneratorConfig `yaml:"hypothesis_generator"`
InvestigationEngine *InvestigationEngineConfig `yaml:"investigation_engine"`
HuntingWorkflow *HuntingWorkflowConfig `yaml:"hunting_workflow"`
KnowledgeBase *KnowledgeBaseConfig `yaml:"knowledge_base"`
CollaborationEngine *CollaborationEngineConfig `yaml:"collaboration_engine"`
AutomationEngine *AutomationEngineConfig `yaml:"automation_engine"`
VisualizationEngine *VisualizationEngineConfig `yaml:"visualization_engine"`
ReportingEngine *ReportingEngineConfig `yaml:"reporting_engine"`
MLEngine *MLEngineConfig `yaml:"ml_engine"`
AIAssistant *AIAssistantConfig `yaml:"ai_assistant"`
}
Additional configuration structures
type ThreatHuntingStats ¶
type ThreatHuntingStats struct {
TotalHunts uint64 `json:"total_hunts"`
ActiveHunts uint64 `json:"active_hunts"`
CompletedHunts uint64 `json:"completed_hunts"`
SuccessfulHunts uint64 `json:"successful_hunts"`
TotalFindings uint64 `json:"total_findings"`
CriticalFindings uint64 `json:"critical_findings"`
TotalInvestigations uint64 `json:"total_investigations"`
ActiveInvestigations uint64 `json:"active_investigations"`
CompletedInvestigations uint64 `json:"completed_investigations"`
AverageHuntDuration time.Duration `json:"average_hunt_duration"`
AverageInvestigationDuration time.Duration `json:"average_investigation_duration"`
ThreatActorsIdentified uint64 `json:"threat_actors_identified"`
CampaignsDiscovered uint64 `json:"campaigns_discovered"`
IOCsGenerated uint64 `json:"iocs_generated"`
HypothesesGenerated uint64 `json:"hypotheses_generated"`
HypothesesValidated uint64 `json:"hypotheses_validated"`
AutomationRate float64 `json:"automation_rate"`
AccuracyRate float64 `json:"accuracy_rate"`
FalsePositiveRate float64 `json:"false_positive_rate"`
TimeToDetection time.Duration `json:"time_to_detection"`
TimeToContainment time.Duration `json:"time_to_containment"`
LastHuntStarted time.Time `json:"last_hunt_started"`
LastInvestigationStarted time.Time `json:"last_investigation_started"`
}
type ThreatHypothesis ¶
type ThreatHypothesis struct {
ID string `json:"id"`
Statement string `json:"statement"`
Rationale string `json:"rationale"`
Assumptions []string `json:"assumptions"`
TestableQuestions []string `json:"testable_questions"`
DataRequirements []*types.DataRequirement `json:"data_requirements"`
ExpectedIndicators []*types.ExpectedIndicator `json:"expected_indicators"`
SuccessCriteria []*types.SuccessCriterion `json:"success_criteria"`
RiskFactors []*types.RiskFactor `json:"risk_factors"`
MITREMapping *types.MITREMapping `json:"mitre_mapping"`
ThreatModeling *types.ThreatModel `json:"threat_modeling"`
Confidence float64 `json:"confidence"`
Probability float64 `json:"probability"`
Severity string `json:"severity"`
Category string `json:"category"`
Tags []string `json:"tags"`
CreatedBy string `json:"created_by"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
ValidationStatus string `json:"validation_status"`
ValidationResults []*types.ValidationResult `json:"validation_results"`
}
ThreatHypothesis represents a hunting hypothesis
type ThreatIntelligenceEngine ¶
type ThreatIntelligenceEngine struct {
// contains filtered or unexported fields
}
ThreatIntelligenceEngine integrates threat intelligence
func NewThreatIntelligenceEngine ¶
func NewThreatIntelligenceEngine(config *IntelligenceEngineConfig, logger *logrus.Logger) (*ThreatIntelligenceEngine, error)
func (*ThreatIntelligenceEngine) EnrichFindings ¶
func (tie *ThreatIntelligenceEngine) EnrichFindings(ctx context.Context, findings []*ThreatFinding) (*IntelligenceResults, error)
type ThreatInvestigation ¶
type ThreatInvestigation struct {
ID string `json:"id"`
Title string `json:"title"`
Description string `json:"description"`
Type string `json:"type"`
Category string `json:"category"`
Status string `json:"status"`
Priority string `json:"priority"`
Severity string `json:"severity"`
Investigators []*types.Investigator `json:"investigators"`
LeadInvestigator string `json:"lead_investigator"`
StartTime time.Time `json:"start_time"`
EndTime *time.Time `json:"end_time,omitempty"`
Duration time.Duration `json:"duration"`
TriggerEvent *types.TriggerEvent `json:"trigger_event"`
InitialFindings []*ThreatFinding `json:"initial_findings"`
HypothesesTested []*ThreatHypothesis `json:"hypotheses_tested"`
EvidenceCollected []*types.Evidence `json:"evidence_collected"`
InterviewsConducted []*types.Interview `json:"interviews_conducted"`
ForensicAnalysis []*types.ForensicAnalysis `json:"forensic_analysis"`
Timeline *types.InvestigationTimeline `json:"timeline"`
RootCause *types.RootCause `json:"root_cause,omitempty"`
AttackChain *types.AttackChain `json:"attack_chain,omitempty"`
ThreatActor *types.ThreatActor `json:"threat_actor,omitempty"`
Campaign *types.ThreatCampaign `json:"campaign,omitempty"`
ImpactAssessment *types.ImpactAssessment `json:"impact_assessment"`
BusinessImpact *types.BusinessImpact `json:"business_impact"`
DataBreach *types.DataBreach `json:"data_breach,omitempty"`
RegulatoryObligations []*types.RegulatoryObligation `json:"regulatory_obligations"`
LegalImplications *types.LegalImplications `json:"legal_implications,omitempty"`
ContainmentActions []*types.ContainmentAction `json:"containment_actions"`
EradicationActions []*types.EradicationAction `json:"eradication_actions"`
RecoveryActions []*types.RecoveryAction `json:"recovery_actions"`
LessonsLearned []*types.LessonLearned `json:"lessons_learned"`
Recommendations []*types.Recommendation `json:"recommendations"`
Reports []*types.InvestigationReport `json:"reports"`
QualityAssurance *types.QualityAssurance `json:"quality_assurance"`
PeerReview *types.PeerReview `json:"peer_review,omitempty"`
ExternalConsultation *types.ExternalConsultation `json:"external_consultation,omitempty"`
Collaboration *types.InvestigationCollaboration `json:"collaboration"`
CommunicationPlan *types.CommunicationPlan `json:"communication_plan"`
Documentation *types.InvestigationDocumentation `json:"documentation"`
Archives []*types.InvestigationArchive `json:"archives"`
CreatedBy string `json:"created_by"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
Tags []string `json:"tags"`
Metadata map[string]interface{} `json:"metadata"`
}
ThreatInvestigation represents a threat investigation
type ThreatKnowledgeBase ¶
type ThreatKnowledgeBase struct{}
func NewThreatKnowledgeBase ¶
func NewThreatKnowledgeBase(config *KnowledgeBaseConfig, logger *logrus.Logger) (*ThreatKnowledgeBase, error)
func (*ThreatKnowledgeBase) StoreHuntResults ¶
func (tkb *ThreatKnowledgeBase) StoreHuntResults(ctx context.Context, hunt *ThreatHunt, results *ThreatHuntResults) error
type VisualizationEngine ¶
type VisualizationEngine struct{}
func NewVisualizationEngine ¶
func NewVisualizationEngine(config *VisualizationEngineConfig, logger *logrus.Logger) (*VisualizationEngine, error)
type VisualizationEngineConfig ¶
type VisualizationEngineConfig struct{}