Show more

I just did a very simple API to query the threat actors from the @MISPProject galaxy. There is a public API and the server is also open source. You can find threat actors name, synonyms and all meta-data with a simple curl query.

github.com/MISP/threat-actor-i …pic.twitter.com/NNjdapbomt

MISP project maintains an exhaustive list of threat actors with metadata, relationships and synonyms. The format is machine-parsable and all is open source under CC-0/2-clause BSD license. Feel free to reuse and/or contribute.

github.com/MISP/misp-galaxy/bl … -
misp-project.org/galaxy.html#_ …pic.twitter.com/lEVgeLgU2o

Happy New Year! Thanks to all the 400+ contributors who contributed to the MISP project to improve information sharing and threat intelligence. Thanks to all the users and supporters who helped during 2019.

misp-project.org/contributors/ pic.twitter.com/JvOe16WMeg

Looking back on 2019 I have learned that by sharing cybersecurity data members of the community are able to lessen the time from first detection anywhere to mitigation. Using a transparent architecture within a SOC like @MISPProject can strength this. .twitter.com/6QP2lED0tO

MISP now supports a new attribute type format for Kusto query used in @Azure Sentinel and Microsoft Defender ATP. You can now share more easily queries within information sharing communities and collaborate on defence. @JohnLaTwC @ashwinpatil
github.com/MISP/MISP/commit/7a …

sightingdb version 0.1 has been released by @tricaud (@devo_Inc) Sighting DB is a fast-lookup database for sightings of attributes. The lookup protocol is a MISP standard which is supported by MISP to have many sighting back-ends.
github.com/stricaud/sightingdb …
misp-standard.org/rfc/sighting …

Don't forget to update your PyMISP library to the latest version especially to fix the issue introduced in the new MISP feed generator.
github.com/MISP/PyMISP/  Thanks to @rafi0t for the hard work and refactoring on the Python library to interact with the MISP API.

In the meantime, community: the best gift you can give this season is not a "hot take", but instead a $ contribution and/or PR to your favorite open source projects!

I released the version 1.0 of git-vuln-finder - Finding potential vulnerabilities in source code repositories by analysing git commit messages.
github.com/cve-search/git-vuln … The next release will include an integration with @MISPProject to allow collaborative review of vulnerabilities.pic.twitter.com/M38GuprQEQ

I would love to see more of the energy currently dedicated to this debate directed to a constructive effort like this. Sigma is underrated. Projects like @MISPProject provide easy means to share sigma/yara/snort sigs alongside contextual information
twitter.com/shotgunner101/stat …

It sounds like @MISPProject may be taking a look at this as well (and are consistently amazing with how fast they develop), but suggest submitting a feature request to
github.com/mitre-attack/tram/i ….

Happy Holidays @MISPProject ! The blue team @Ubisoft present MISP-K8S: automated high availability MISP + MISP Dashboard deployment in @awscloud EKS.

vvx7.io/posts/2019/12/misp-hig …
@Xyrodileas @apleks_

Thanks! Now this should lower the bar for adopting @MITREattack. Maybe in a Future release you add the Option for sharing new sub-techniques via @MISPProject.
twitter.com/MITREattack/status …

Thanks to @mokaddem_sami for the incredible @MISPProject cookie. Don’t forget we have a flexible data model for information sharing and we even have a cookie object template ;-)
misp-project.org/objects.html# …pic.twitter.com/ObNB6M0KEg

New @apivoid expansion module for MISP, @circl_lu passive dns and passive SSL/TLS modules have now support for MISP objects (passive DNS and x.509 objects) and many improvements in misp-modules. Thanks to @chrisred_68 and all the contributors.
misp.github.io/misp-modules/ex …pic.twitter.com/Y0hOvM3Tbq

Last Friday we had the first meeting. A big thank you to all participants, good discussions and exchange of ideas on @MISPProject . Presentations are up at
github.com/cudeso/misp-usergro … Stay tuned for the Doodle announcing the next date(s).

Definitely can recommend markdown to make the integration with the upcoming report objects easier

Show more
OpenCloud Luxembourg Mastodon instance

A Mastodon instance for Luxembourg and beyond.