DefensePointSecurity / threat_note

DPS' Lightweight Investigation Notebook
Apache License 2.0
421 stars 97 forks source link

FR: Threat Actor overhaul #139

Open CyberIntelJunkie opened 8 years ago

CyberIntelJunkie commented 8 years ago

Threat Actors (http://0.0.0.0:5000/threatactors) feel empty as they stand right now. When I think of Threat Actors, I think of a collection of attributes/indicators associated with an actor, versus right now, it feels like any other indicator.

Issue 1: Threat actors feel like indicators

Issue 2: No easy way to tie indicators/campaigns to actors

Issue 3: No way to export all indicators associated with actor

Now I understand this is a big enhancement and may not be possible with the current database or layout. Love the project and the commitment you guys are showing. I personally feel like if these requests add bloat or complexity, it may not be worth it to add since threat_note is awesome at being lightweight and simple.

brianwarehime commented 8 years ago

I apologize for getting to this so late, as I've been updating the other issues, I've been swamped and in between moves right now. In about two weeks, I'll be able to sit down and go over all the suggestions you've made and work with the others that have been helping and talk through some of the development and database changes in the works.

Thanks for all your suggestions, really great feedback! Again, sorry I can't dig into this right away, but, it's definitely on my plate and I will review it as soon as I can.

CyberIntelJunkie commented 8 years ago

No worries, life happens. Thanks for checking in and leaving updates! Happy to help wherever I can.