For advanced users, Actions can be created at the socket level to ingest specific TTPs . This Action type uses a basic TCP or UDP connection that data is sent over. This is helpful when a PCAP is not available.
- From the Director, go to Library > Actions.
- Click Add Action and then select Socket. The Add Socket Action form displays.
- Select Comm Type (TCP or UDP) and enter the Server port.
- Add Step information:
- Click on the Step 1 label to expand the step.
- Enter the Request.
- Optional: Enter the Response.
- If you want to add additional steps, click Add Another Step and then repeat steps b & c.
Adding steps to socket-based Actions
- After all steps are entered, click Next.
- Populate the Action Name, Description, and Dimensions.
- Name
- Description
- Attack Vector
- Attacker Location
- Behavior Type
- Covert
- OS/Platform
- Stage of Attacks
- Optional: User Tags
- Click Save Action. The Action Library displays. A confirmation message that your Action was created successfully is shown and the Action is selected and displayed in the Action preview.