MISP for automated threat analysis and storing
MISP (https://www.misp-project.org/) is an open source TI platform for automation, analysis, and intelligence sharing. I recommend MISP for small and medium enterprises with limited resources. We start with the default MISP configurations, and we can then add extra data feeds later.
The following sections allow us to automate and store the previous analysis.
MISP feed management
Collecting the correct external data can be challenging. MISP allows integration with several feeds and comes with a set of free feeds (https://www.circl.lu/doc/misp/managing-feeds/). The following points provide steps to enable the feeds:
- Log in to the MISP dashboard using the
admin@admin.test
username andadmin
password. You will be requested to change the password on the first login. - Navigate to Sync Actions > List Feeds.
- Click on Default feeds, select all, and enable them. The feeds will be enabled for correlation with our analysis...