Course of action#
A course of action details a set of clear, specific recommendations and measures to mitigate an incident, address affected exploit targets, and effectively respond to a cyber threat.
The goal of a course of action can be preventing the potential occurrence of an incident, correcting a vulnerability so that it cannot be exploited, mitigating the consequences of an attack, or defeating an adversary.
Regardless of the goal, a course of action suggests the recommended actions to take in order to achieve the intended effect.
Create a course of action by selecting:
In the side navigation bar + Create > Course of action.
Or:
(Requires Beta: Intelligence creation on the graph)
In the top navigation bar of a graph, select + and then Course of action to create a draft entity.
Double-click to open the newly created draft entity to edit it.
Then, Configure this entity.
Configure#
The following sections the fields and options available.
Note
Required fields are marked with an asterisk (*).
General#
Field |
EIQ JSON field |
Description |
---|---|---|
Title* |
|
Descriptive title for this entity. See Titles and aliases. |
Analysis |
|
Long description of course of action. |
Characteristics#
Characteristics are properties on an entity that provide context for the intelligence indicated by this object.
The following are characteristics available for courses of action:
Characteristics: Type#
Field |
EIQ JSON field |
Description |
---|---|---|
Type |
|
Type of course of action. Analogous to CourseOfActionTypeVocab-1.0 Available options:
|
Characteristics: Stage#
Field |
EIQ JSON field |
Description |
---|---|---|
Stage |
|
Stage of course of action. Analogous to COAStageVocab-1.0 Available options:
|
Characteristics: Objective#
Describes the objective of this course of action. Analogous to ObjectiveType
Field |
EIQ JSON field |
Description |
---|---|---|
Description |
|
Describes objective. |
Applicability confidence |
|
A confidence value. Possible values from Enumerated values: High Medium low. |
Characteristics: Impact#
Describes the impact of this course of action.
Field |
EIQ JSON field |
Description |
---|---|---|
Impact value* |
|
Possible values from Enumerated values: High Medium low. |
Confidence |
|
A confidence value. Possible values from Enumerated values: High Medium low. |
Description |
|
Description of impact. |
Characteristics: Cost#
Describes the cost of this course of action.
Field |
EIQ JSON field |
Description |
---|---|---|
Cost value* |
|
Possible values from Enumerated values: High Medium low. |
Confidence |
|
A confidence value. Possible values from Enumerated values: High Medium low. |
Description |
|
Description of cost. |
Characteristics: Efficacy#
Describes the efficacy of this course of action.
Field |
EIQ JSON field |
Description |
---|---|---|
Efficacy value* |
|
Possible values from Enumerated values: High Medium low. |
Confidence |
|
A confidence value. Possible values from Enumerated values: High Medium low. |
Description |
|
Description of efficacy. |
Observables#
You can create one or more new observables and link it to the currently open entity by selecting + Observable under the Observables section.
Note
If an observable you create here matches an observable rule with an ignore action, it does not appear when the you publish the entity.
In the Add observable view that appears, fill out these fields:
Field |
EIQ JSON field |
Description |
---|---|---|
Type* |
|
See Observable types |
Link name* |
||
Values(s)* |
|
Enter one or more values. One observable is created per value. Values must be comma-separated, or newline-separated, but not both. |
Maliciousness* |
Relations#
Add relationships to this entity by selecting + Relationship.
From the drop-down menu select the option corresponding to the relationship you want to create:
After selecting an option, the Search an entity dialog appears. Select one or more entities to relate to the current entity.
Note
You can narrow down the displayed entities by entering a search query, or by using the filter .
Select Select to add the selected entities as relations.
Once a relationship is added to this entity, you can:
Assign MITRE ATT&CK IDs by selecting + under the MITRE ATT&CK IDs column.
Set a Relationship type
Enter a custom relationship type by typing in the empty field and pressing ENTER to save.
Select one of these options:
Indicates malware
Is associated campaign to
I don’t know
Could be anything
Meta#
The Meta section contains configuration options that allow you to attach descriptive data to the entity.
Field |
EIQ JSON field |
Description |
---|---|---|
Estimated threat start time |
|
Estimated start of threat. See Time values. |
Estimated threat end time |
|
Estimated end of threat. See Time values. |
Estimated observed time |
|
Estimated time threat was observed. See Time values. |
Half-life |
|
See Half-life. Select one of these options:
|
Tags |
|
See tags and taxonomies. |
Source* |
|
Select one source. |
Source reliability |
|
See source reliability. Options:
|
Information source#
Field |
EIQ JSON field |
Description |
---|---|---|
Description |
|
Description of information source. |
Identity |
|
Name of this information source |
Roles |
|
One or more information source roles. Possible values:
|
References |
|
One or more URLs. |
Data marking#
Descriptive metadata for entity.
Field |
EIQ JSON field |
Description |
---|---|---|
TLP |
|
Set a TLP color for this entity. |
Terms of use |
|
Free text field allowing you to attach terms of use to an entity. Analogous to TermsOfUseMarkingStructureType. |
Simple |
|
Free text field for attaching any text to an entity. Analogous to SimpleMarkingStructureType. |
Workflow#
Use options here to apply workflow options to this entity.
Field |
Description |
---|---|
Add to dataset |
Select this option to add this entity to one or more datasets on Publish. |
Manually enrich |
Run one or more enrichers on this entity on Publish. |
Save and publish#
Tip
For more information, see Draft and published entities.
Select Publish to create this entity, and make it available under + Create > Production > Published.
For more publishing options, select More and then one of these options:
Publish and new: Publish this entity, and start creating a new entity.
Publish and duplicate: Publish this entity, and start creating a new entity using all the values set for this entity.
Select Save draft to save this entity as a draft, and make it available under + Create > Production > Drafts. You must publish an entity to use it elsewhere on EclecticIQ Intelligence Center.
For more options while saving as a draft, select More and then one of these options:
Publish and new: Save this entity as a draft, and start creating a new entity.
Publish and duplicate: Save this entity as a draft, and start creating a new entity using all the values set for this draft entity.