cudeso / misp2sentinel

MISP to Sentinel integration
MIT License
52 stars 17 forks source link

New type of Indicator: IBAN #60

Open Teobotti opened 9 months ago

Teobotti commented 9 months ago

Is it possible to include new type of indicators like IBAN codes? (on Upload Indicators API) CERTs are starting to use MISP to share IBAN as Indicators of Fraud (IoF), the integration of these indicators in the SIEM can automate several processes and can give more value to MISP platform itself. If Sentinel does not accept the new indicator, is it possible to add the value in the name or description field without creating errors?

jusso-dev commented 4 months ago

@Teobotti Hey there! can you share an example STIX message or just message in general that is an IBAN message just so I can see the format? I don't know of any Sentinel support for this field type, but we could definitely just add this as metadata to the message, depending on what it looks like.