Posts

Showing posts with the label Threat Analysis

Osweep - Don't Simply Search Osint, Sweep It

Image
If you lot operate inward information technology security, therefore you lot most probable role OSINT to assistance you lot sympathise what it is that your SIEM alerted you lot on together with what everyone else inward the globe understands most it. More than probable you lot are using to a greater extent than than 1 OSINT service because most of the fourth dimension OSINT volition entirely render you lot amongst reports based on the final analysis of the IOC. For some, that's practiced enough. They do network together with electronic mail blocks, do novel rules for their IDS/IPS, update the content inward the SIEM, do novel alerts for monitors inward Google Alerts together with DomainTools, etc etc. For others, they deploy these same countermeasures based on provided reports from their third-party tools that the fellowship is paying THOUSANDS of dollars for. The work amongst both of these is that the analyst needs to dig a footling deeper (ex. FULLY deobfuscate a PowerShel...

Misp - Malware Data Sharing Platform As Well As Threat Sharing

Image
The objective of MISP is to foster the sharing of structured information inside the safety community as well as abroad. MISP provides functionalities to back upward the telephone commutation of information but also the consumption of the information past times Network Intrusion Detection System (NIDS), LIDS but also log analysis tools, SIEMs.MISP, is an opened upward source software solution for collecting, storing, distributing as well as sharing cyber safety indicators as well as threat close cyber safety incidents analysis as well as malware analysis. MISP is designed past times as well as for incident analysts, safety as well as ICT professionals or malware reverser to back upward their day-to-day operations to portion structured informations efficiently. MISP, Malware Information Sharing Platform as well as Threat Sharing, heart as well as mortal functionalities are: An efficient IOC as well as indicators database allowing to shop technical as well as non-technical in...