-
Notifications
You must be signed in to change notification settings - Fork 418
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[RFC] Threat intelligence #986
Conversation
Stage 0 submission for threat intelligence
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for opening @shimonmodi!
I've added a few minor review comments, but I think overall this looks good to advance to stage 0.
See #1023 for a proposal on how to map IOC fields specifically. |
Co-authored-by: Eric Beahan <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @shimonmodi for making those changes! I'll assign the RFC # and merge the PR to advance to stage 0.
Thanks @ebeahan and @shimonmodi 👍 Next step Shimon is simply to open a new PR for stage 1. You can start very quick by just changing "stage 0" to "stage 1" at the top of the doc, open the PR right away with only this change, and mark it as a draft. Then you can work on the content of the stage 1 doc as time allows and push to that PR over time. Opening the stage 1 quickly will give us a place to drop any further feedback and ideas on this, in the meantime. |
@webmat - thanks for the next steps. I just completed them. |
Question on the excel sheet mappings - is it necessary to nest e.g. file, host, user, process, etc. under threat - or would it make more sense to use the top level fields in combination with the threat fields to make the overall document naming simpler? |
@dainperkins Discussion about this should continue on the next stage PR, here #1037 |
Stage 0 submission for threat intelligence
make test
?make
and committed those changes?Markdown preview of this RFC