Skip to content

Commit

Permalink
Add content to Introduction section
Browse files Browse the repository at this point in the history
  • Loading branch information
lion-gu committed Jul 18, 2019
1 parent ea4ac6c commit 4dee06a
Showing 1 changed file with 2 additions and 10 deletions.
12 changes: 2 additions & 10 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,17 +4,9 @@

## Introduction

Indicator of Compromise (IOC) threat hunting
Correlating Indicator of Compromise (IOC) is a key part of incident investigation even threat hunting. Finding one IP address hosting several known malicious files would help SOC teams to implement more effective countermeasure by blocking that IP address. However, building a correlation usually means a lot of manual work, like searching multiple IOCs across different threat intelligence sources (community sources or private sources). Sometimes, correlation can only be found after several iterative queries.

problem

multiple sources: community sources or paid sources

repeat input

random choose

major advantage
IOC Explorer aims to execute iterative queries across multiple threat intelligence sources automatically. It may assist security analyst to find more clues for investigation.

## Quick Start

Expand Down

0 comments on commit 4dee06a

Please sign in to comment.