IOC Management
#1089
Replies: 1 comment
-
Thanks for the kind words! IOC management is a good question that I have been considering as well. Currently you could use custom fields, as you suggested, for that. They are only strings at the moment, but could be extended. Another option would be to add a minimal assets/IOC tracking or integration with MISP and/or OpenCTI. So the options summarized would be:
I'll investigate what makes the most sense here, but I'm also happy to take suggestions. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I like the minimalist approach - in my opinion, TheHive is now far too overloaded, especially for small teams. Do I understand correctly that the custom fields can be used for IOCs? Can domain, IPv4c URL etc. be created as a type with the respective value? Can this data also be tagged, e.g. "malicious"? And last question: retrievable via API for MISP etc.? :)
Beta Was this translation helpful? Give feedback.
All reactions