You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is your feature request related to a problem? Please describe.
The challenge with misp today is that misp is event centric, thats great for dealing with events, but dealing with the indicators fron an IOC centric view its a bit harder. Using misp as an IOC database works, kind of, but it could be improved greatly.
Describe the solution you'd like
MISP could benefit from an IOC centric view in addition to the event view that exists today, by this i mean that the indicators themselves are in focus, comments follow the indicator, the indicator as a whole can be enabled or disabled for IDS, regardless of existing in multiple events or not, and the different events the IOC exists in are viewed as context. one is able to comment the indicator freely of the events the indicator might or might not exist in. Indicators could even exist not in an event but in the IOC database. Maybe some of this is doable, maybe some of this is completely crazy and not possible to achive but im thinking aloud here from my own experience with misp. It would make it possible to further use misp as a tool for analysts.
needs triageThis issue has been automatically labelled and needs further triage
1 participant
Converted from issue
This discussion was converted from issue #8060 on December 30, 2021 08:31.
Heading
Bold
Italic
Quote
Code
Link
Numbered list
Unordered list
Task list
Attach files
Mention
Reference
Menu
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
-
Is your feature request related to a problem? Please describe.
The challenge with misp today is that misp is event centric, thats great for dealing with events, but dealing with the indicators fron an IOC centric view its a bit harder. Using misp as an IOC database works, kind of, but it could be improved greatly.
Describe the solution you'd like
MISP could benefit from an IOC centric view in addition to the event view that exists today, by this i mean that the indicators themselves are in focus, comments follow the indicator, the indicator as a whole can be enabled or disabled for IDS, regardless of existing in multiple events or not, and the different events the IOC exists in are viewed as context. one is able to comment the indicator freely of the events the indicator might or might not exist in. Indicators could even exist not in an event but in the IOC database. Maybe some of this is doable, maybe some of this is completely crazy and not possible to achive but im thinking aloud here from my own experience with misp. It would make it possible to further use misp as a tool for analysts.
Describe alternatives you've considered
No response
Additional context
No response
Code of Conduct
Beta Was this translation helpful? Give feedback.
All reactions