SEKOIA-IO / SEKOIA.IO-for-Splunk

Increase your Splunk capabilities with SEKOIA.IO Integration
Apache License 2.0
4 stars 1 forks source link

Additional fields #7

Open P01s0nV opened 2 years ago

P01s0nV commented 2 years ago

We would like to have additional fields for iocs in the SEKOIA lookups. More precisely, we would like to have the name of the threat and the mitre attack phase, which seem to be available in the SEKOIA.IO API.

We were also wondering if there was a reputation attached to iocs, and if so, if it could be added as well ?

CharlesLR-sekoia commented 2 years ago

Dear @P01s0nV

Thank you for this request. This is indeed an interesting point.

This is an open source feature, we would be please to review your code for:

I think that information collection related to Threats is much more complex than it may seems to be.

Should you have other questions, feel free to contact support@sekoia.io

Best regards,