cyb3rfox / Aurora-Incident-Response

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders
Apache License 2.0
758 stars 81 forks source link

OSINT tab #48

Closed PeterM1981 closed 3 years ago

PeterM1981 commented 3 years ago

In the world of IR one of the most common things we are facing atm is the large scale ransomware attacks. My team regularly has open engagements for the same threat groups (Maze, DoppelPaymer, Ryuk, REvil, etc etc). It would be useful if we could have a dedicated OSINT section in the "Investigation" section. To start with this could just be a place to paste links to articles, whitepapers etc.

In future versions though, if it was linked to APIs and was automatically displaying OSINT information relating to IOCs that had been entered into the timeline. For example if I added a C2 address then the OSINT page might provide links to articles, tweets, sandbox results, shodan, VT, anything that referenced that C2 address.

cyb3rfox commented 3 years ago

Good idea! I'll add that

cyb3rfox commented 3 years ago

Fixed. Will be in the next release.