Skip to content
Discussion options

You must be logged in to vote

Zeek Intel is nice because you can just dump a list of indicators into the configuration (domain names, IPs, file hashes, etc.) and then it will trigger an alert if one of them shows up.

MISP can generate Intel rules automatically, so that's a good way to go from "my ISAC sent me this spreadsheet of IOCs" to a detection in minimal time.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@InfosecGoon
Comment options

Answer selected by subs1138
@subs1138
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants