TheHive-Project / Cortex

Cortex: a Powerful Observable Analysis and Active Response Engine
https://thehive-project.org
GNU Affero General Public License v3.0
1.32k stars 227 forks source link

Trying to understand Cortex #390

Open fear-the-reaper opened 2 years ago

fear-the-reaper commented 2 years ago

Hi! I'm having trouble understanding Cortex and how it helps threat intelligence like is it some sort of data aggregator or does it do some sort of correlation of some data collected. Furthermore how and why do you connect it to MISP, TheHive, etc. Lastly, what are these analyzers and such?

nrrpinto commented 2 years ago

My suggestion is that you read the documentation, you can start with these ones: https://github.com/TheHive-Project/CortexDocs https://thehive-project.github.io/Cortex-Analyzers/