Case study – the fictional Shadow Bunny corporation
Let's introduce our players and the network we deal with. Our fictitious Shadow Bunny corporation is a small team with a variety of assets that might be attacked. Many employees use Windows managed by an Active Directory domain. However, there are macOS and Linux devices in the organization, and some employees have phones that they use for work also.
Let's walk through an example of how to model and import described assets into a graph database. The key point to demonstrate is that we will merge in datasets from many different sources to build out a knowledge graph for situational awareness.
But let's look at our practical example on how to model for a better home-field advantage. As a starting point, we need to define our data model and what it is that we would like to model.
Employees and assets
For the purposes of research and education, this chapter will create a new database (knowledge graph...