CERN-CERT / pDNSSOC

Leveraging MISP indicators via a pDNS-based infrastructure as a poor man’s SOC.
MIT License
49 stars 5 forks source link

Update sightings for MISP IOCs detected #17

Open arvchristos opened 11 months ago

arvchristos commented 11 months ago

MISP provides an API to add or remove sightings for each attribute. Should we detect a match, we can increase the sightings number, helping to curate more valuable events by providing direct feedback.

Relevant PyMISP method: https://pymisp.readthedocs.io/en/latest/modules.html#pymisp.PyMISP.add_sighting