idaholab / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://idaholab.github.io/Malcolm/
Other
349 stars 59 forks source link

investigate Zeek's javascript MISP interface as an improvement to existing Zeek intel MISP integration #270

Open mmguero opened 11 months ago

mmguero commented 11 months ago

In the Zeek community call October 4, 2023, Arne Welzel gave a demo of a new Zeek demo using javascript to interface with MISP.

Christian Kreibich says in the next few days there will be blog posts on the Zeek and Corelight blogs about this.

This may be better than what we're currently doing with MISP (?). We should look into it.

mmguero commented 10 months ago

Here's the blog post

mmguero commented 8 months ago

Another blog post