hunting

package
v1.5.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 18, 2025 License: MIT Imports: 8 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func NewHypothesisGenerator

func NewHypothesisGenerator(config *types.HypothesisGeneratorConfig, logger *logrus.Logger) (*types.HypothesisGenerator, error)

Types

type AIAssistantConfig

type AIAssistantConfig struct{}

type AIHuntingAssistant

type AIHuntingAssistant struct{}

func NewAIHuntingAssistant

func NewAIHuntingAssistant(config *AIAssistantConfig, logger *logrus.Logger) (*AIHuntingAssistant, error)

func (*AIHuntingAssistant) GenerateInsights

func (aia *AIHuntingAssistant) GenerateInsights(ctx context.Context, hunt *ThreatHunt, results *ThreatHuntResults) (*AIInsights, error)

type AIInsights

type AIInsights struct{}

type AdvancedThreatHunter

type AdvancedThreatHunter struct {
	// contains filtered or unexported fields
}

AdvancedThreatHunter - The most sophisticated threat hunting system Revolutionizes proactive threat detection with AI-powered hunting capabilities

func NewAdvancedThreatHunter

func NewAdvancedThreatHunter(config *ThreatHuntingConfig, logger *logrus.Logger) (*AdvancedThreatHunter, error)

NewAdvancedThreatHunter creates a new advanced threat hunting system

func (*AdvancedThreatHunter) ExecuteHunt

func (th *AdvancedThreatHunter) ExecuteHunt(ctx context.Context, huntID string) (*ThreatHuntResults, error)

ExecuteHunt executes the threat hunting process

func (*AdvancedThreatHunter) GenerateHypothesis

func (th *AdvancedThreatHunter) GenerateHypothesis(ctx context.Context, request *HypothesisRequest) (*ThreatHypothesis, error)

GenerateHypothesis generates a threat hunting hypothesis

func (*AdvancedThreatHunter) GetActiveHunts

func (th *AdvancedThreatHunter) GetActiveHunts() []*ThreatHunt

GetActiveHunts returns all active threat hunts

func (*AdvancedThreatHunter) GetActiveInvestigations

func (th *AdvancedThreatHunter) GetActiveInvestigations() []*ThreatInvestigation

GetActiveInvestigations returns all active investigations

func (*AdvancedThreatHunter) GetHuntingStats

func (th *AdvancedThreatHunter) GetHuntingStats() *ThreatHuntingStats

GetHuntingStats returns threat hunting statistics

func (*AdvancedThreatHunter) StartInvestigation

func (th *AdvancedThreatHunter) StartInvestigation(ctx context.Context, request *InvestigationRequest) (*ThreatInvestigation, error)

StartInvestigation initiates a threat investigation

func (*AdvancedThreatHunter) StartThreatHunt

func (th *AdvancedThreatHunter) StartThreatHunt(ctx context.Context, request *ThreatHuntRequest) (*ThreatHunt, error)

StartThreatHunt initiates a new threat hunt

type AnalyticResults

type AnalyticResults struct{}

type AnomalyDetector

type AnomalyDetector struct {
	// contains filtered or unexported fields
}

AnomalyDetector identifies anomalous activities

func NewAnomalyDetector

func NewAnomalyDetector(config *AnomalyDetectorConfig, logger *logrus.Logger) (*AnomalyDetector, error)

type AnomalyDetectorConfig

type AnomalyDetectorConfig struct{}

type AutomationEngine

type AutomationEngine struct{}

func NewAutomationEngine

func NewAutomationEngine(config *AutomationEngineConfig, logger *logrus.Logger) (*AutomationEngine, error)

func (*AutomationEngine) StartAutomatedHunt

func (ae *AutomationEngine) StartAutomatedHunt(ctx context.Context, hunt *ThreatHunt) error

type AutomationEngineConfig

type AutomationEngineConfig struct{}

type BehaviorAnalyzer

type BehaviorAnalyzer struct {
	// contains filtered or unexported fields
}

BehaviorAnalyzer analyzes behavioral patterns for threats

func NewBehaviorAnalyzer

func NewBehaviorAnalyzer(config *BehaviorAnalyzerConfig, logger *logrus.Logger) (*BehaviorAnalyzer, error)

type BehaviorAnalyzerConfig

type BehaviorAnalyzerConfig struct{}

Additional configuration stubs

type CollaborationEngine

type CollaborationEngine struct{}

func NewCollaborationEngine

func NewCollaborationEngine(config *CollaborationEngineConfig, logger *logrus.Logger) (*CollaborationEngine, error)

func (*CollaborationEngine) NotifyHuntCompleted

func (ce *CollaborationEngine) NotifyHuntCompleted(ctx context.Context, hunt *ThreatHunt, results *ThreatHuntResults) error

func (*CollaborationEngine) NotifyHuntStarted

func (ce *CollaborationEngine) NotifyHuntStarted(ctx context.Context, hunt *ThreatHunt) error

type CollaborationEngineConfig

type CollaborationEngineConfig struct{}

type CorrelationEngine

type CorrelationEngine struct {
	// contains filtered or unexported fields
}

CorrelationEngine correlates events and indicators

func NewCorrelationEngine

func NewCorrelationEngine(config *CorrelationEngineConfig, logger *logrus.Logger) (*CorrelationEngine, error)

func (*CorrelationEngine) CorrelateFindings

func (ce *CorrelationEngine) CorrelateFindings(ctx context.Context, findings []*ThreatFinding) (*CorrelationResults, error)

type CorrelationEngineConfig

type CorrelationEngineConfig struct{}

type CorrelationResults

type CorrelationResults struct{}

type HuntAnalytic

type HuntAnalytic struct {
	Name string `json:"name"`
}

type HuntPhase

type HuntPhase struct {
	ID         string           `json:"id"`
	Name       string           `json:"name"`
	Techniques []*HuntTechnique `json:"techniques"`
	Queries    []*HuntQuery     `json:"queries"`
	Analytics  []*HuntAnalytic  `json:"analytics"`
}

type HuntPhaseResults

type HuntPhaseResults struct {
	PhaseID    string                  `json:"phase_id"`
	PhaseName  string                  `json:"phase_name"`
	StartTime  time.Time               `json:"start_time"`
	EndTime    time.Time               `json:"end_time"`
	Duration   time.Duration           `json:"duration"`
	Success    bool                    `json:"success"`
	Findings   []*ThreatFinding        `json:"findings"`
	Evidence   []*types.Evidence       `json:"evidence"`
	IOCs       []*types.IOC            `json:"iocs"`
	Techniques []*types.MITRETechnique `json:"techniques"`
}

type HuntQuery

type HuntQuery struct {
	Name string `json:"name"`
}

type HuntReport

type HuntReport struct{}

type HuntStrategy

type HuntStrategy struct {
	ID                 string                       `json:"id"`
	Name               string                       `json:"name"`
	Type               string                       `json:"type"`
	Methodology        string                       `json:"methodology"`
	Framework          string                       `json:"framework"`
	Phases             []*HuntPhase                 `json:"phases"`
	Techniques         []*HuntTechnique             `json:"techniques"`
	DataSources        []*types.DataSource          `json:"data_sources"`
	Tools              []*types.HuntTool            `json:"tools"`
	Queries            []*HuntQuery                 `json:"queries"`
	Analytics          []*HuntAnalytic              `json:"analytics"`
	Playbooks          []*types.HuntPlaybook        `json:"playbooks"`
	Automations        []*types.HuntAutomation      `json:"automations"`
	SuccessMetrics     []*types.SuccessMetric       `json:"success_metrics"`
	KillChainMapping   *types.KillChainMapping      `json:"kill_chain_mapping"`
	TacticsMapping     map[string][]string          `json:"tactics_mapping"`
	AdversaryEmulation *types.AdversaryEmulation    `json:"adversary_emulation"`
	RedTeamScenarios   []*types.RedTeamScenario     `json:"red_team_scenarios"`
	ThreatIntelligence *types.ThreatIntelligenceReq `json:"threat_intelligence"`
	CollaborationModel *types.CollaborationModel    `json:"collaboration_model"`
	QualityAssurance   *types.QualityAssurance      `json:"quality_assurance"`
}

HuntStrategy defines hunting approach and methodology

type HuntTechnique

type HuntTechnique struct {
	Name string `json:"name"`
}

type HuntingEngine

type HuntingEngine struct {
	// contains filtered or unexported fields
}

HuntingEngine orchestrates threat hunting activities

func NewHuntingEngine

func NewHuntingEngine(config *HuntingEngineConfig, logger *logrus.Logger) (*HuntingEngine, error)

func (*HuntingEngine) DetermineStrategy

func (he *HuntingEngine) DetermineStrategy(ctx context.Context, hypothesis *ThreatHypothesis, request *ThreatHuntRequest) (*HuntStrategy, error)

Additional method stubs

type HuntingEngineConfig

type HuntingEngineConfig struct {
	Enabled            bool    `yaml:"enabled"`
	StrategiesPath     string  `yaml:"strategies_path"`
	PlaybooksPath      string  `yaml:"playbooks_path"`
	AutoExecute        bool    `yaml:"auto_execute"`
	ParallelExecution  bool    `yaml:"parallel_execution"`
	MaxConcurrentHunts int     `yaml:"max_concurrent_hunts"`
	DefaultTimeout     string  `yaml:"default_timeout"`
	QualityThreshold   float64 `yaml:"quality_threshold"`
}

Placeholder configurations - these would be fully implemented

type HuntingWorkflow

type HuntingWorkflow struct{}

Additional type stubs

func NewHuntingWorkflow

func NewHuntingWorkflow(config *HuntingWorkflowConfig, logger *logrus.Logger) (*HuntingWorkflow, error)

func (*HuntingWorkflow) InitializeWorkflow

func (hw *HuntingWorkflow) InitializeWorkflow(ctx context.Context, hunt *ThreatHunt) (*HuntingWorkflow, error)

type HuntingWorkflowConfig

type HuntingWorkflowConfig struct{}

type HypothesisGenerator

type HypothesisGenerator struct {
	// contains filtered or unexported fields
}

HypothesisGenerator generates hunting hypotheses

type HypothesisGeneratorConfig

type HypothesisGeneratorConfig struct{}

type HypothesisRequest

type HypothesisRequest struct {
	ThreatType   string              `json:"threat_type"`
	ThreatActors []string            `json:"threat_actors"`
	Techniques   []string            `json:"techniques"`
	Tactics      []string            `json:"tactics"`
	DataSources  []*types.DataSource `json:"data_sources"`
	Environment  *types.Environment  `json:"environment"`
	Context      string              `json:"context"`
	Priority     string              `json:"priority"`
	RequestedBy  string              `json:"requested_by"`
	Tags         []string            `json:"tags"`
}

type IndicatorEngine

type IndicatorEngine struct {
	// contains filtered or unexported fields
}

IndicatorEngine manages and analyzes threat indicators

func NewIndicatorEngine

func NewIndicatorEngine(config *IndicatorEngineConfig, logger *logrus.Logger) (*IndicatorEngine, error)

type IndicatorEngineConfig

type IndicatorEngineConfig struct {
	Enabled        bool     `yaml:"enabled"`
	IOCFeeds       []string `yaml:"ioc_feeds"`
	CustomIOCs     bool     `yaml:"custom_iocs"`
	IOCExpiration  string   `yaml:"ioc_expiration"`
	IOCScoring     bool     `yaml:"ioc_scoring"`
	IOCEnrichment  bool     `yaml:"ioc_enrichment"`
	IOCCorrelation bool     `yaml:"ioc_correlation"`
}

type IntelligenceEngineConfig

type IntelligenceEngineConfig struct{}

type IntelligenceResults

type IntelligenceResults struct{}

type InvestigationEngine

type InvestigationEngine struct {
	// contains filtered or unexported fields
}

InvestigationEngine supports threat investigations

func NewInvestigationEngine

func NewInvestigationEngine(config *InvestigationEngineConfig, logger *logrus.Logger) (*InvestigationEngine, error)

func (*InvestigationEngine) InitializeInvestigation

func (ie *InvestigationEngine) InitializeInvestigation(ctx context.Context, investigation *ThreatInvestigation) error

type InvestigationEngineConfig

type InvestigationEngineConfig struct{}

type InvestigationRequest

type InvestigationRequest struct {
	Title            string                    `json:"title"`
	Description      string                    `json:"description"`
	Type             string                    `json:"type"`
	Category         string                    `json:"category"`
	Priority         string                    `json:"priority"`
	Severity         string                    `json:"severity"`
	Investigators    []*types.Investigator     `json:"investigators"`
	LeadInvestigator string                    `json:"lead_investigator"`
	TriggerEvent     *types.TriggerEvent       `json:"trigger_event"`
	InitialFindings  []*ThreatFinding          `json:"initial_findings"`
	Scope            *types.InvestigationScope `json:"scope"`
	Timeline         *types.TimeRange          `json:"timeline"`
	InitiatedBy      string                    `json:"initiated_by"`
	Tags             []string                  `json:"tags"`
	Metadata         map[string]interface{}    `json:"metadata"`
}

type KnowledgeBaseConfig

type KnowledgeBaseConfig struct{}

type MLEngineConfig

type MLEngineConfig struct{}

type MLHuntingEngine

type MLHuntingEngine struct{}

func NewMLHuntingEngine

func NewMLHuntingEngine(config *MLEngineConfig, logger *logrus.Logger) (*MLHuntingEngine, error)

func (*MLHuntingEngine) AnalyzeHuntResults

func (mle *MLHuntingEngine) AnalyzeHuntResults(ctx context.Context, results *ThreatHuntResults) (*MLResults, error)

type MLResults

type MLResults struct{}

type QueryResults

type QueryResults struct{}

type ReportingEngine

type ReportingEngine struct{}

func NewReportingEngine

func NewReportingEngine(config *ReportingEngineConfig, logger *logrus.Logger) (*ReportingEngine, error)

func (*ReportingEngine) GenerateHuntReport

func (re *ReportingEngine) GenerateHuntReport(ctx context.Context, hunt *ThreatHunt, results *ThreatHuntResults) (*HuntReport, error)

type ReportingEngineConfig

type ReportingEngineConfig struct{}

type TechniqueResults

type TechniqueResults struct {
	Findings   []*ThreatFinding        `json:"findings"`
	Evidence   []*types.Evidence       `json:"evidence"`
	IOCs       []*types.IOC            `json:"iocs"`
	Techniques []*types.MITRETechnique `json:"techniques"`
}

type ThreatFinding

type ThreatFinding struct {
	ID                  string                     `json:"id"`
	Type                string                     `json:"type"`
	Category            string                     `json:"category"`
	Severity            string                     `json:"severity"`
	Confidence          float64                    `json:"confidence"`
	Title               string                     `json:"title"`
	Description         string                     `json:"description"`
	Summary             string                     `json:"summary"`
	ThreatActor         *types.ThreatActor         `json:"threat_actor,omitempty"`
	Campaign            *types.ThreatCampaign      `json:"campaign,omitempty"`
	Techniques          []*types.MITRETechnique    `json:"techniques"`
	Tactics             []string                   `json:"tactics"`
	IOCs                []*types.IOC               `json:"iocs"`
	Evidence            []*types.Evidence          `json:"evidence"`
	Timeline            *types.FindingTimeline     `json:"timeline"`
	AffectedAssets      []*types.AffectedAsset     `json:"affected_assets"`
	DataExfiltration    *types.DataExfiltration    `json:"data_exfiltration,omitempty"`
	LateralMovement     *types.LateralMovement     `json:"lateral_movement,omitempty"`
	Persistence         *types.Persistence         `json:"persistence,omitempty"`
	PrivilegeEscalation *types.PrivilegeEscalation `json:"privilege_escalation,omitempty"`
	DefenseEvasion      *types.DefenseEvasion      `json:"defense_evasion,omitempty"`
	CommandAndControl   *types.CommandAndControl   `json:"command_and_control,omitempty"`
	Impact              *types.ThreatImpact        `json:"impact"`
	RiskScore           float64                    `json:"risk_score"`
	BusinessImpact      *types.BusinessImpact      `json:"business_impact"`
	Recommendations     []*types.Recommendation    `json:"recommendations"`
	RemediationSteps    []*types.RemediationStep   `json:"remediation_steps"`
	ContainmentActions  []*types.ContainmentAction `json:"containment_actions"`
	EradicationActions  []*types.EradicationAction `json:"eradication_actions"`
	RecoveryActions     []*types.RecoveryAction    `json:"recovery_actions"`
	LessonsLearned      []string                   `json:"lessons_learned"`
	Attribution         *types.Attribution         `json:"attribution,omitempty"`
	GeographicContext   *types.GeographicContext   `json:"geographic_context,omitempty"`
	IndustryContext     *types.IndustryContext     `json:"industry_context,omitempty"`
	RegulatoryImpact    *types.RegulatoryImpact    `json:"regulatory_impact,omitempty"`
	ForensicArtifacts   []*types.ForensicArtifact  `json:"forensic_artifacts"`
	RelatedFindings     []string                   `json:"related_findings"`
	ExternalReferences  []*types.ExternalReference `json:"external_references"`
	DiscoveredBy        string                     `json:"discovered_by"`
	DiscoveredAt        time.Time                  `json:"discovered_at"`
	UpdatedAt           time.Time                  `json:"updated_at"`
	Status              string                     `json:"status"`
	AssignedTo          []string                   `json:"assigned_to"`
	Priority            string                     `json:"priority"`
	Tags                []string                   `json:"tags"`
	Metadata            map[string]interface{}     `json:"metadata"`
}

ThreatFinding represents a discovered threat

type ThreatHunt

type ThreatHunt struct {
	ID                 string                     `json:"id"`
	Name               string                     `json:"name"`
	Description        string                     `json:"description"`
	Hypothesis         *ThreatHypothesis          `json:"hypothesis"`
	Strategy           *HuntStrategy              `json:"strategy"`
	Status             string                     `json:"status"`
	Priority           string                     `json:"priority"`
	Hunters            []string                   `json:"hunters"`
	StartTime          time.Time                  `json:"start_time"`
	EndTime            *time.Time                 `json:"end_time,omitempty"`
	Duration           time.Duration              `json:"duration"`
	Progress           float64                    `json:"progress"`
	Findings           []*ThreatFinding           `json:"findings"`
	Evidence           []*types.Evidence          `json:"evidence"`
	IOCs               []*types.IOC               `json:"iocs"`
	Indicators         []*types.ThreatIndicator   `json:"indicators"`
	Techniques         []*types.MITRETechnique    `json:"techniques"`
	Tactics            []string                   `json:"tactics"`
	ActorProfile       *types.ThreatActorProfile  `json:"actor_profile,omitempty"`
	Campaign           *types.ThreatCampaign      `json:"campaign,omitempty"`
	Confidence         float64                    `json:"confidence"`
	RiskScore          float64                    `json:"risk_score"`
	Impact             *types.ThreatImpact        `json:"impact"`
	Recommendations    []*types.Recommendation    `json:"recommendations"`
	Artifacts          []*types.HuntArtifact      `json:"artifacts"`
	Timeline           *types.HuntTimeline        `json:"timeline"`
	Collaborators      []*types.Collaborator      `json:"collaborators"`
	AutomationLevel    string                     `json:"automation_level"`
	QualityScore       float64                    `json:"quality_score"`
	LessonsLearned     []string                   `json:"lessons_learned"`
	NextSteps          []string                   `json:"next_steps"`
	RelatedHunts       []string                   `json:"related_hunts"`
	ExternalReferences []*types.ExternalReference `json:"external_references"`
	Metadata           map[string]interface{}     `json:"metadata"`
}

ThreatHunt represents an active threat hunt

type ThreatHuntRequest

type ThreatHuntRequest struct {
	Name            string                 `json:"name"`
	Description     string                 `json:"description"`
	Priority        string                 `json:"priority"`
	Hunters         []string               `json:"hunters"`
	Hypothesis      *ThreatHypothesis      `json:"hypothesis,omitempty"`
	Strategy        *HuntStrategy          `json:"strategy,omitempty"`
	DataSources     []*types.DataSource    `json:"data_sources"`
	TimeRange       *types.TimeRange       `json:"time_range"`
	Scope           *types.HuntScope       `json:"scope"`
	AutomationLevel string                 `json:"automation_level"`
	InitiatedBy     string                 `json:"initiated_by"`
	Tags            []string               `json:"tags"`
	Metadata        map[string]interface{} `json:"metadata"`
}

type ThreatHuntResults

type ThreatHuntResults struct {
	HuntID              string                  `json:"hunt_id"`
	StartTime           time.Time               `json:"start_time"`
	EndTime             time.Time               `json:"end_time"`
	Duration            time.Duration           `json:"duration"`
	Findings            []*ThreatFinding        `json:"findings"`
	Evidence            []*types.Evidence       `json:"evidence"`
	IOCs                []*types.IOC            `json:"iocs"`
	Techniques          []*types.MITRETechnique `json:"techniques"`
	CorrelationResults  *CorrelationResults     `json:"correlation_results,omitempty"`
	IntelligenceResults *IntelligenceResults    `json:"intelligence_results,omitempty"`
	MLResults           *MLResults              `json:"ml_results,omitempty"`
	AIInsights          *AIInsights             `json:"ai_insights,omitempty"`
	Report              *HuntReport             `json:"report,omitempty"`
	Success             bool                    `json:"success"`
	QualityScore        float64                 `json:"quality_score"`
}

type ThreatHuntingConfig

type ThreatHuntingConfig struct {
	HuntingEngine       *HuntingEngineConfig             `yaml:"hunting_engine"`
	IndicatorEngine     *IndicatorEngineConfig           `yaml:"indicator_engine"`
	BehaviorAnalyzer    *BehaviorAnalyzerConfig          `yaml:"behavior_analyzer"`
	AnomalyDetector     *AnomalyDetectorConfig           `yaml:"anomaly_detector"`
	CorrelationEngine   *CorrelationEngineConfig         `yaml:"correlation_engine"`
	IntelligenceEngine  *IntelligenceEngineConfig        `yaml:"intelligence_engine"`
	HypothesisGenerator *types.HypothesisGeneratorConfig `yaml:"hypothesis_generator"`
	InvestigationEngine *InvestigationEngineConfig       `yaml:"investigation_engine"`
	HuntingWorkflow     *HuntingWorkflowConfig           `yaml:"hunting_workflow"`
	KnowledgeBase       *KnowledgeBaseConfig             `yaml:"knowledge_base"`
	CollaborationEngine *CollaborationEngineConfig       `yaml:"collaboration_engine"`
	AutomationEngine    *AutomationEngineConfig          `yaml:"automation_engine"`
	VisualizationEngine *VisualizationEngineConfig       `yaml:"visualization_engine"`
	ReportingEngine     *ReportingEngineConfig           `yaml:"reporting_engine"`
	MLEngine            *MLEngineConfig                  `yaml:"ml_engine"`
	AIAssistant         *AIAssistantConfig               `yaml:"ai_assistant"`
}

Additional configuration structures

type ThreatHuntingStats

type ThreatHuntingStats struct {
	TotalHunts                   uint64        `json:"total_hunts"`
	ActiveHunts                  uint64        `json:"active_hunts"`
	CompletedHunts               uint64        `json:"completed_hunts"`
	SuccessfulHunts              uint64        `json:"successful_hunts"`
	TotalFindings                uint64        `json:"total_findings"`
	CriticalFindings             uint64        `json:"critical_findings"`
	TotalInvestigations          uint64        `json:"total_investigations"`
	ActiveInvestigations         uint64        `json:"active_investigations"`
	CompletedInvestigations      uint64        `json:"completed_investigations"`
	AverageHuntDuration          time.Duration `json:"average_hunt_duration"`
	AverageInvestigationDuration time.Duration `json:"average_investigation_duration"`
	ThreatActorsIdentified       uint64        `json:"threat_actors_identified"`
	CampaignsDiscovered          uint64        `json:"campaigns_discovered"`
	IOCsGenerated                uint64        `json:"iocs_generated"`
	HypothesesGenerated          uint64        `json:"hypotheses_generated"`
	HypothesesValidated          uint64        `json:"hypotheses_validated"`
	AutomationRate               float64       `json:"automation_rate"`
	AccuracyRate                 float64       `json:"accuracy_rate"`
	FalsePositiveRate            float64       `json:"false_positive_rate"`
	TimeToDetection              time.Duration `json:"time_to_detection"`
	TimeToContainment            time.Duration `json:"time_to_containment"`
	LastHuntStarted              time.Time     `json:"last_hunt_started"`
	LastInvestigationStarted     time.Time     `json:"last_investigation_started"`
}

type ThreatHypothesis

type ThreatHypothesis struct {
	ID                 string                     `json:"id"`
	Statement          string                     `json:"statement"`
	Rationale          string                     `json:"rationale"`
	Assumptions        []string                   `json:"assumptions"`
	TestableQuestions  []string                   `json:"testable_questions"`
	DataRequirements   []*types.DataRequirement   `json:"data_requirements"`
	ExpectedIndicators []*types.ExpectedIndicator `json:"expected_indicators"`
	SuccessCriteria    []*types.SuccessCriterion  `json:"success_criteria"`
	RiskFactors        []*types.RiskFactor        `json:"risk_factors"`
	MITREMapping       *types.MITREMapping        `json:"mitre_mapping"`
	ThreatModeling     *types.ThreatModel         `json:"threat_modeling"`
	Confidence         float64                    `json:"confidence"`
	Probability        float64                    `json:"probability"`
	Severity           string                     `json:"severity"`
	Category           string                     `json:"category"`
	Tags               []string                   `json:"tags"`
	CreatedBy          string                     `json:"created_by"`
	CreatedAt          time.Time                  `json:"created_at"`
	UpdatedAt          time.Time                  `json:"updated_at"`
	ValidationStatus   string                     `json:"validation_status"`
	ValidationResults  []*types.ValidationResult  `json:"validation_results"`
}

ThreatHypothesis represents a hunting hypothesis

type ThreatIntelligenceEngine

type ThreatIntelligenceEngine struct {
	// contains filtered or unexported fields
}

ThreatIntelligenceEngine integrates threat intelligence

func NewThreatIntelligenceEngine

func NewThreatIntelligenceEngine(config *IntelligenceEngineConfig, logger *logrus.Logger) (*ThreatIntelligenceEngine, error)

func (*ThreatIntelligenceEngine) EnrichFindings

func (tie *ThreatIntelligenceEngine) EnrichFindings(ctx context.Context, findings []*ThreatFinding) (*IntelligenceResults, error)

type ThreatInvestigation

type ThreatInvestigation struct {
	ID                    string                            `json:"id"`
	Title                 string                            `json:"title"`
	Description           string                            `json:"description"`
	Type                  string                            `json:"type"`
	Category              string                            `json:"category"`
	Status                string                            `json:"status"`
	Priority              string                            `json:"priority"`
	Severity              string                            `json:"severity"`
	Investigators         []*types.Investigator             `json:"investigators"`
	LeadInvestigator      string                            `json:"lead_investigator"`
	StartTime             time.Time                         `json:"start_time"`
	EndTime               *time.Time                        `json:"end_time,omitempty"`
	Duration              time.Duration                     `json:"duration"`
	TriggerEvent          *types.TriggerEvent               `json:"trigger_event"`
	InitialFindings       []*ThreatFinding                  `json:"initial_findings"`
	HypothesesTested      []*ThreatHypothesis               `json:"hypotheses_tested"`
	EvidenceCollected     []*types.Evidence                 `json:"evidence_collected"`
	InterviewsConducted   []*types.Interview                `json:"interviews_conducted"`
	ForensicAnalysis      []*types.ForensicAnalysis         `json:"forensic_analysis"`
	Timeline              *types.InvestigationTimeline      `json:"timeline"`
	RootCause             *types.RootCause                  `json:"root_cause,omitempty"`
	AttackChain           *types.AttackChain                `json:"attack_chain,omitempty"`
	ThreatActor           *types.ThreatActor                `json:"threat_actor,omitempty"`
	Campaign              *types.ThreatCampaign             `json:"campaign,omitempty"`
	ImpactAssessment      *types.ImpactAssessment           `json:"impact_assessment"`
	BusinessImpact        *types.BusinessImpact             `json:"business_impact"`
	DataBreach            *types.DataBreach                 `json:"data_breach,omitempty"`
	RegulatoryObligations []*types.RegulatoryObligation     `json:"regulatory_obligations"`
	LegalImplications     *types.LegalImplications          `json:"legal_implications,omitempty"`
	ContainmentActions    []*types.ContainmentAction        `json:"containment_actions"`
	EradicationActions    []*types.EradicationAction        `json:"eradication_actions"`
	RecoveryActions       []*types.RecoveryAction           `json:"recovery_actions"`
	LessonsLearned        []*types.LessonLearned            `json:"lessons_learned"`
	Recommendations       []*types.Recommendation           `json:"recommendations"`
	Reports               []*types.InvestigationReport      `json:"reports"`
	QualityAssurance      *types.QualityAssurance           `json:"quality_assurance"`
	PeerReview            *types.PeerReview                 `json:"peer_review,omitempty"`
	ExternalConsultation  *types.ExternalConsultation       `json:"external_consultation,omitempty"`
	Collaboration         *types.InvestigationCollaboration `json:"collaboration"`
	CommunicationPlan     *types.CommunicationPlan          `json:"communication_plan"`
	Documentation         *types.InvestigationDocumentation `json:"documentation"`
	Archives              []*types.InvestigationArchive     `json:"archives"`
	CreatedBy             string                            `json:"created_by"`
	CreatedAt             time.Time                         `json:"created_at"`
	UpdatedAt             time.Time                         `json:"updated_at"`
	Tags                  []string                          `json:"tags"`
	Metadata              map[string]interface{}            `json:"metadata"`
}

ThreatInvestigation represents a threat investigation

type ThreatKnowledgeBase

type ThreatKnowledgeBase struct{}

func NewThreatKnowledgeBase

func NewThreatKnowledgeBase(config *KnowledgeBaseConfig, logger *logrus.Logger) (*ThreatKnowledgeBase, error)

func (*ThreatKnowledgeBase) StoreHuntResults

func (tkb *ThreatKnowledgeBase) StoreHuntResults(ctx context.Context, hunt *ThreatHunt, results *ThreatHuntResults) error

type VisualizationEngine

type VisualizationEngine struct{}

func NewVisualizationEngine

func NewVisualizationEngine(config *VisualizationEngineConfig, logger *logrus.Logger) (*VisualizationEngine, error)

type VisualizationEngineConfig

type VisualizationEngineConfig struct{}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL