OSINT
STUDENT USE ONLY
Copyright 2020, Ervin Frenzel
Student:
(LastName)_____________________(FirstName)_______________
Class______________________Section______________Semester:___________________
Week:________________Project:___________________________________
Copyright 2020, Ervin Frenzel
Instructions:
For identifying SIEM/Security products:
Identify and rank 10 components (data sets or logs) that can be imported to a SIEM - rank them
upon, do this with 2 separate SIEM products (LogRythm, Splunk, QRadar, ArcSight, AlienVault,
NuSiem, Dell SecureWorks, Rapid 7) Rank according to Application Programming Interface
(API):
API rating "0" - Data integration is not possible with non-proprietary data sets
API rating "1" - manual retrieval of information
API rating "2" - We can produce API
API rating "3" - Community will produce API
API rating "4" - Organization will produce and deploy API
API rating "5" - Existing API produced and backed by Vendor
For Cost Associations (Highest cost to Lowest cost):
1 – ________________ to _________________ (example over $50,000)
2 – ________________ to _________________ (example $40,000 to $49,999)
3 – ________________ to _________________ (example $25,000 to $39,999)
4 – ________________ to _________________ (example $10,000 to $24,999)
5 – ________________ to _________________ (example under $9,999)
For Identifying Indicators of Compromise (IoC):
Rank according to:
1 – No association (validated or confirmed)
2 – Suspected not association
3 – Association unknown (status unknown)
4 – Suspected association
5 – Association confirmed (validated or confirmed)
- LastName:
- FirstName:
- Class:
- Section:
- Semester:
- Week:
- Project:
- 1:
- to:
- 2:
- to_2:
- 3:
- to_3:
- 4:
- to_4:
- 5:
- to_5:
- Value 1:
- 0:
- 0:
- 1:
- 2:
- 3:
- 4:
- 5:
- 6:
- 1:
- 0:
- 1:
- 2:
- 3:
- 4:
- 5:
- 6:
- 2:
- 0:
- 1:
- 2:
- 3:
- 4:
- 5:
- 6:
- 3:
- 0:
- 1:
- 2:
- 3:
- 4:
- 5:
- 6:
- 4:
- 0:
- 1:
- 2:
- 3:
- 4:
- 5:
- 6:
- 5:
- 0:
- 1:
- 2:
- 3:
- 4:
- 5:
- 6:
- 6:
- 0:
- 1:
- 2:
- 3:
- 4:
- 5:
- 6:
- 7:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 0:
- 1:
- 8:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 0:
- 1:
- 9:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 0:
- 1:
- 10:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 0:
- 1:
- 11:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 0:
- 1:
- 12:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 13:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 14:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 15:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 16:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 17:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 18:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 19:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 20:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 0:
- 1:
- 0:
- 1:
- 6:
- 0:
- 1:
- 0:
- 1:
- 21:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 0:
- 1:
- 3:
- 0:
- 1:
- 0:
- 1:
- 4:
- 0:
- 1:
- 0:
- 1:
- 5:
- 1:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 0:
- 1:
- 22:
- 0:
- 0:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 1:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 2:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 3:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 2:
- 0:
- 1:
- 4:
- 2:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 5:
- 2:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1:
- 0:
- 0:
- 1:
- 1:
- 0:
- 1: