The document discusses the Zeek network analysis framework, focusing on its role in network security monitoring and correlation of intelligence with ATT&CK metrics. It outlines the architecture, ecosystem, and processes involved in mapping threat intelligence to ATT&CK, including data preparation, correlation, and alerting techniques. The document emphasizes the importance of effective data modeling and preparation for improving analysis capabilities in security operations.
Related topics: