Writing Meaningful Threat Intel Reports in MISP
On the occasion of the FIRST conference that took place from 6-8 JUNE 2021, Alexandre Dulaunoy, Andras Iklody & Sami Mokaddem (CIRCL) gave a training about Writing Meaningful threat Intel Reports in MISP.
Threat information comes in many different shapes and sizes.
We are used to receiving information from our peers, internal tools and from vendors, but the usefulness of the information hinges in large part on how well information is expressed and contextualised.
This training aims at walking us through the process of taking our source information that we wish to share with the community and turning it into something both actionable as well as expressive and contextualised enough for it to be truly useful for a wide range of audiences.