Enterprise-grade platforms have to integrate with other enterprise solutions in order to be effective. SCYTHE focuses on providing business value through adversary emulation and showing whether security tools and controls are properly implemented and tuned to detect malicious behavior. To implement an enterprise solution, SCYTHE integrates with other solutions such as Splunk, PlexTrac, VECTR, and virtually any solution or SIEM via syslog.
This post covers how to integrate your SCYTHE instances with Splunk as well as a project by Splunk’s Security Strategist, Tim Frazier, called ATT&CK Simulator. ATT&CK Simulator brings a number of components together for automating adversary emulation and correlating with detective data in Splunk. ATT&CK Simulator leverages Splunk’s Phantom runbooks to run SCYTHE campaigns via SCYTHE API and then correlates the attack data with Splunk’s detective data (logs from sysmon, windows event, etc), including Olaf Hartong's ThreatHunting App (we spoke with Olaf and introduced Sysmon in our Ransomware #ThreatThursday).
We linked up with Tim Frazier, Splunk’s Security Strategist and creator of ATT&CK Simulator, along with Kyle Champlin and David Herrald, to discuss this new tool. ATT&CK Simulator integrates ATT&CK Navigator, SCYTHE, Phantom, Olaf Hartong's ThreatHunting App, and Splunk to run automated adversary emulation campaigns that correlate with detection data. As documented in the Github readme, you will be able to repeatedly execute specific techniques, observe the resulting events in Splunk and refine your detection rules and methodology.
At a high level and all from within Splunk:
SCYTHE is easily integrated with Spunk by filling out three fields in the “Administration - Settings” menu as shown in Figure 1 (screenshot from SCYTHE Administrator Guide):
The Splunk Host, Key, and Port information comes straight from your Splunk instance’s HTTP Event Collector. The Administration Guide you receive when you purchase SCYTHE provides a step-by-step walkthrough. For completeness, these are the steps:
SCYTHE provides an advanced attack emulation platform for the enterprise and cybersecurity consulting market. The SCYTHE platform enables Red, Blue, and Purple teams to build and emulate real-world adversarial campaigns in a matter of minutes. Customers are in turn enabled to validate the risk posture and exposure of their business and employees and the performance of enterprise security teams and existing security solutions. Based in Arlington, VA, the company is privately held and is funded by Gula Tech Adventures, Paladin Capital, Evolution Equity, and private industry investors. For more information email info@scythe.io, visit https://scythe.io, or follow on Twitter @scythe_io.