Skip to content

Commit 27c41ce

Browse files
author
jdv
committed
ready for reaview
1 parent 25a0aab commit 27c41ce

File tree

1 file changed

+22
-35
lines changed

1 file changed

+22
-35
lines changed

crowdsec-docs/unversioned/troubleshooting/usecases.mdx

Lines changed: 22 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -94,7 +94,7 @@ Quickly choose among qualified malicious actors regrouped by industry, behaviors
9494
**How it works:**
9595
- Stream CrowdSec IP Lists into your security tools.
9696
- Integrate directly in your security tools thanks to our integrations or easy to use CTI API.
97-
- 🏅 Get custom IOC streams made for your needs.([contact us ↗️](https://www.crowdsec.net/business-requests?interest=CTI%20subscription))
97+
- 🏅 Get custom IOC streams made for your needs.
9898
- Next step: Enrich IPs via CrowdSec CTI API.
9999

100100

@@ -104,6 +104,7 @@ Quickly choose among qualified malicious actors regrouped by industry, behaviors
104104
- [Retrieving Blocklists via API](/u/console/service_api/quickstart/blocklists#download-blocklist-content)
105105
- [MISP Feed from Security Engine's alerts](https://doc.crowdsec.net/u/bouncers/misp-feed-generator)
106106
- [Upcoming CrowdSec MISP Feeds ↗️](https://roadmap.crowdsec.net/c/48-misp-feed)
107+
- [Contact Us for custom requests ↗️](https://www.crowdsec.net/business-requests?interest=CTI%20subscription))
107108

108109
---
109110

@@ -202,20 +203,20 @@ Accelerate incident response with contextual threat intelligence and automated r
202203

203204
**Is it for me?**
204205
Ideal if your SOC team is overwhelmed with security alerts and needs better context for prioritization.
205-
Good option if you want to automate alert enrichment and reduce time-to-response for security incidents.
206+
Add exclusive context to your alerts and automate incident response with up to 30+ IP reputation enrichment dimensions.
206207

207208
**How it works:**
208-
- Configure notification plugins to automatically enrich alerts with global threat intelligence context.
209-
- Set up CTI helpers in templates to add reputation data, attack patterns, and geographic context.
210-
- Deploy operational dashboards for SOC teams to visualize threats and track security metrics.
211-
- Integrate with existing SIEM/SOAR tools to enhance existing alert workflows.
209+
- Consult CrowdSec CTI: per IP queries, advanced search on behavior, classifications or performed CVEs- Configure notification plugins to automatically enrich alerts with global threat intelligence context.
210+
- Obtain your CTI API key from your CrowdSec Console account or a contact with CrowdSec team for higher quotas.
211+
- Integrate it in your tools with out existing integrations or via simple calls to the API.
212+
- 🏅 Advanced usages: API search, Offline replication, ...
212213

213214
**References**
214-
- [Notification plugins configuration](/docs/next/notification_plugins/intro)
215-
- [CTI helpers in templates](/docs/next/notification_plugins/template_helpers)
216-
- [Monitoring dashboards setup](/docs/next/cscli/cscli_dashboard)
217-
- [Metrics tracking with cscli](/docs/next/cscli/cscli_metrics)
218-
- [Console enrollment for CTI access](/docs/next/cscli/cscli_console_enroll)
215+
- [Explore CrowdSec CTI within the console](/u/cti_api/getting_started)
216+
- [Create a test API key](/u/cti_api/api_getting_started)
217+
- [IP reputation enrichment glossary](/u/cti_api/taxonomy/cti_object)
218+
- [Evaluate your IPs using our **IPDEX** tool](/u/cti_api/api_integration/integration_ipdex/)
219+
- [Contact Us for 🏅 advanced usage ↗️](https://www.crowdsec.net/business-requests?interest=CTI%20subscription)
219220

220221
---
221222

@@ -228,32 +229,18 @@ Ideal if you have a threat hunting team that needs fresh, contextual intelligenc
228229
Good option if you want to correlate local events with global attack patterns and emerging threats.
229230

230231
**How it works:**
231-
- Enroll your Security Engine in CrowdSec Console to access global CTI and CVE correlation data.
232-
- Use the web interface to investigate threat patterns and analyze attack trends.
233-
- Correlate your local security events with global crowd-sourced intelligence.
234-
- Export enriched threat data for integration with your existing threat hunting tools and workflows.
232+
- Explore our CTI and CVE explorer
233+
- Leverage advanced search capabilities to identify relevant threats and vulnerabilities.
234+
- Go further using our CTI API to integrate threat intelligence into your existing workflows.
235235

236236
**References**
237-
- [Console enrollment guide](/docs/next/cscli/cscli_console_enroll)
238-
- [CTI integration documentation](/u/console/blocklists/subscription/)
239-
- [Global threat intelligence access](/u/integrations/intro)
240-
- [VulnTracking Reports](https://www.crowdsec.net/blog) (Monthly CVE analysis)
241-
- [Threat investigation workflows](/docs/next/cscli/cscli_decisions)
237+
- [CTI related refs from **Alert Enhancement and Triage**](#alert-enhancement-and-triage)
238+
- [CVE explorer](/u/cti_api/cve_explorer/)
239+
- [IPDEX presentation article ↗️](https://www.crowdsec.net/blog/introducing-crowdsec-ipdex)
240+
- [Follow our weekly vuln report on LinkedIn ↗️](https://www.linkedin.com/company/crowdsec/posts/?feedView=all)
242241

243242
---
244243

245-
## Getting Started Resources
246-
247-
If you're new to CrowdSec, start with these foundational guides:
248-
249-
* [Install CrowdSec Security Engine](/u/getting_started/installation/linux)
250-
* [Configure log data sources](/docs/next/data_sources/file)
251-
* [Understand bouncers and remediation](/docs/next/cscli/cscli_bouncers)
252-
* [Set up Local API](/docs/next/local_api/intro)
253-
* [Complete health check guide](/u/getting_started/health_check)
254-
255-
## Related Documentation
256-
257-
* [Security Engine Troubleshooting](./security_engine)
258-
* [Remediation Components Troubleshooting](./remediation_components)
259-
* [CTI Integration Guide](./cti)
244+
## Useful Links
245+
- [CrowdSec Public Roadmap ↗️](https://roadmap.crowdsec.net/tabs/3-planned)
246+
- [CrowdSec GitHub Repository ↗️](https://github.com/crowdsecurity/)

0 commit comments

Comments
 (0)