The artifact and observable repositories
Once intelligence and data are collected, where are they stored? Often an afterthought in the collection management process, the storage and maintenance of intelligence and related data is an important discipline, often carried out by individuals solely tasked with that function in the collection team. While there are many options for how to store intelligence and data, very broadly speaking, artifact and observable data repositories are simply intelligence and data stores that facilitate the following high-level objectives:
- The ability to store threat intelligence data in a normalized and efficient fashion
- The ability to access, filter, search, and query threat intelligence data
- API feed functionality to access threat intelligence data
- The ability to facilitate role-based access
- The ability to be modular in nature, supporting diverse threat data ingestion via diverse transport mechanisms, such as Structured Threat Information...