PaloAltoNetworks / minemeld

Main MineMeld documentation repo
379 stars 64 forks source link

MineMeld End-of-Life (in Autofocus) #60

Open idev opened 3 years ago

idev commented 3 years ago

Hello MineMeld Users,

I am wondering if anybody else is concerned by the move of Palo Alto no longer providing a MineMeld instance via Autofocus. Are there any alternatives to self-hosting a MineMeld Server, like MineMeld as a Service (Saas)?

Kind regards

xhoms commented 3 years ago

What about running its containerized version in any managed container infrastructure like AWS's ECS?

idev commented 3 years ago

The idea of SaaS is, not to be responsible for operations in any form. A containerized version would delegate this responsibility back to the "owner".

xhoms commented 3 years ago

Fair enough. AFAIK Palo Alto Networks' XSOAR TIM is the supported product for Thread Intel Management and it can be delivered as a fully hosted solution.

I'm not aware of any company providing open source MineMeld as a managed service.

idev commented 3 years ago

Thank you! I am aware of XSOAR TIM, but as far as I know this only provides a subset of the features Minemeld has?! Main feature is generating a IP / URL / Domain List from sources to feed a dynamic firewall rule (EDL).

xhoms commented 3 years ago

I'm afraid XSOAR TIM might be a super-set instead. Maybe too featured for a basic EDL feed application.