ShareTide, or how we are Open Sourcing 200+ OpenTide Threat Objects and building a community to accelerate Detection Engineering #22
behemothsecurity
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
ShareTide & WikiTide
Enabling world-scale OpenTide collaboration
We're making the first step towards integrating OpenTide deeper into the Detection Engineering ecosystem by releasing more than 200 Threat Vectors that were developed at the European Commission CSOC CATCH team, all
TLP:CLEAR, for the benefit of Detection Engineers worldwide.The new
ShareTide, and generated documentation projectWikiTideempower Detection Engineers with already researched and processed intelligence, inter-related into rich attack graphs. It is a project open to the community and encouraging contributions.Our broader vision is to enable teams to continuously share and ingest OpenTide objects across distributed repositories and MISP instances, using systemic usage of UUIDv4 as a foundation to avoid duplication. The teams can decide to cherry pick objects of interest and start developing detection rules, benefiting from the modelling work accomplished by the larger detection engineering community. With the initial ShareTide infrastructure, we're now able to maintain a public OpenTide instance. Our next steps will be to open source detection models, and enable automated sharing capabilities over git and MISP.
All reactions