New @MISPProject playbook! Tackle the week with JARM fingerprint investigations to track threat actor infrastructure using @censysio, @shodanhq, and MISP. Boost your #cti game with #automation and #infrastructure insights. https://t.co/qNDGmD937h
Kick off the week with a new @MISPProject playbook! Query Elasticsearch @elastic for threat intelligence from custom MISP searches, plot the results in a graph, report sightings in MISP, and send a summary to Mattermost. #cti#automation#playbooks https://t.co/NzaCjO7mWz
The MISP galaxy evolved into a complete set of knowledge base freely accessible to many projects including MISP. At the EU ATT&CK community workshop, we presented the recommendations for models creator:
Slides: https://t.co/XoaZ4K04JZ
#threatintelligence@cvandeplas@adulau
This week, our team had an exciting catch-up with the CIRCL Luxembourg team! Check out the highlights from our meeting and other updates from AUSCERT! 💖
Week in Review available now for 17.05.24! 💥
https://t.co/29UGU0qQom
A new @MISPProject playbook to help with curation of decayed indicators. Use the custom model of the playbook or one of the MISP build-in models. Decayed indicators are disabled and tagged. #cti https://t.co/1BGOARflQk
If you haven't used the @MISPProject playbooks before then have a look at the @jupyterthon presentation I did last week. https://t.co/r0rVBfbWv8 Great work by all participants in showing how @ProjectJupyter notebooks can support #infosec
Do you know that @circl_lu create many free #OSINT tools dedicated to the community?
One of my favorites is the #AIL (Analysis of Information Leaks) framework.
You want to know more about it? Retrieve @adulau's talk recorded at @_leHACK_#OsintVillage.
https://t.co/2MDB2BiJvo
The MISP galaxy is expanding rapidly. To facilitate easier navigation through its diverse clusters, we have developed a dedicated website.
https://t.co/iO6HH6Wxns
https://t.co/LxnmDML4wc
#threatintel#threatintelligence#misp#opensource
https://t.co/GkMtK9bUop
MISP 2.4.179 released with a host of improvements a security fix and some new tooling. New steps taken towards LLM integration, Workflow improvements, performance improvements for large edit and many more...
#opensource#threatinte#misp
If you liked the previous @MISPProject playbook for static malware analysis then you're certainly going to like this one. This playbook extends the results with dynamic malware analysis by the sandboxes from @vmray , @HybridAnalysis and @virustotal https://t.co/MKvVB0nNbn
I shared the @MISPProject playbook for malware triage that I regularly use for a first assessment on new samples. It uses MISP, @virustotal , MalwareBazaar, Hashlookup and pefile, uploads to MWDB and alerts to Mattermost. #csirt#ir#dfir https://t.co/tgOmnJtsZ4
Use the "MISP playbook on Kali" documentation to deploy @MISPProject playbooks on a Kali VM, for example during an incident investigation. https://t.co/1W6jHmMGf2
There's a new @MISPProject playbook that shows how to create users and organisations, get user logs and create large number of users at once (fe. for trainings). All with PyMISP. https://t.co/IQ8s02MAar) , inspired by misp_control from @rommelfs https://t.co/hVFR58Ch5o
Excited for @hack_lu! In addition to my planned talk, I'll conduct a 90-min workshop to introduce Kunai: your new Linux threat-hunting tool (an alternative to #SysmonForLinux). See you there! More info: https://t.co/qv8hqFKC5y