<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use Case in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Use-Case/m-p/669301#M9816</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259920"&gt;@gmbdrj&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's realli diffi coult to answer to your question in few words.&lt;/P&gt;&lt;P&gt;A&amp;gt;nyway, installi the MItre &lt;A href="mailto:Att@ck" target="_blank"&gt;Att@ck&lt;/A&gt;&amp;nbsp;app, you can start from a mapping of your Searches with this framework.&lt;/P&gt;&lt;P&gt;Then you can use the Enterprise Security (if you have) and/or the Splunk Security Essentials App to be guided in Use Cases implementation.&lt;/P&gt;&lt;P&gt;Anyway, remember that the starting poins is always data: you have to analyze the data you have to understand which Use Cases you can enable.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2023 07:53:56 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-11-21T07:53:56Z</dc:date>
    <item>
      <title>Use Case</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Use-Case/m-p/669270#M9815</link>
      <description>&lt;DIV&gt;&lt;SPAN&gt;I'm trying to make SOC Use cases clear, concise, and easy to find later. It is possible to make a threat detection use case based on MITRE, but I guess SOC is not the only threat detection. There are many other requirements such as compliance and business use cases. What approach should be more effective and right?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Here are my questions.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Use Case Development:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Best practices for effective SOC use cases and recommended frameworks?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Documentation and Knowledge Management:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Strategies/tools for organizing SOC use cases for searchability?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Continuous Improvement:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Methods for improving and updating SOC use cases over time?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Can you share examples of how penetration testing results have influenced the development of SOC use cases?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Risk Assessment Integration:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- How do you align SOC use cases with risk levels identified in risk assessments?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Are there specific metrics or indicators from risk assessments that should be incorporated into SOC use cases?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- What best practices do you suggest for regularly reviewing and updating SOC use cases based on changes in risk assessments?&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 21 Nov 2023 02:54:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Use-Case/m-p/669270#M9815</guid>
      <dc:creator>gmbdrj</dc:creator>
      <dc:date>2023-11-21T02:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: Use Case</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Use-Case/m-p/669301#M9816</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259920"&gt;@gmbdrj&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's realli diffi coult to answer to your question in few words.&lt;/P&gt;&lt;P&gt;A&amp;gt;nyway, installi the MItre &lt;A href="mailto:Att@ck" target="_blank"&gt;Att@ck&lt;/A&gt;&amp;nbsp;app, you can start from a mapping of your Searches with this framework.&lt;/P&gt;&lt;P&gt;Then you can use the Enterprise Security (if you have) and/or the Splunk Security Essentials App to be guided in Use Cases implementation.&lt;/P&gt;&lt;P&gt;Anyway, remember that the starting poins is always data: you have to analyze the data you have to understand which Use Cases you can enable.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 07:53:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Use-Case/m-p/669301#M9816</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-21T07:53:56Z</dc:date>
    </item>
  </channel>
</rss>

