MISP / misp-playbooks

MISP Playbooks
https://misp.github.io/misp-playbooks/
BSD 2-Clause "Simplified" License
167 stars 16 forks source link

Create a MISP event from a Sentinel incident #34

Closed cudeso closed 2 months ago

cudeso commented 1 year ago

The title of the playbook

Create a MISP event from a Sentinel incident

Purpose of the playbook

Investigate possibilities for creating MISP events from Sentinel incident (ref. follow up post on sending indicators from MISP to Sentinel)

Sources for inspiration:

External resources used by this playbook

Azure

Target audience

SOC, CSIRT, CTI

Breefly list the execution steps or workflow

No response