Collection of best practices to add OSINT into MISP and/or MISP communities
Go to file
2023-09-29 22:33:27 +02:00
version-1 chg: [dir] original version moved to version 1 2019-07-20 12:16:56 +02:00
version-2 chg: [dir] version 2 directory instead of the format name 2019-07-20 11:56:17 +02:00
version-3 <Parsing Graph> 2020-01-11 23:56:30 +01:00
version-4 <Parsing Graph> 2020-01-11 23:56:30 +01:00
version-5 added version 5 2023-09-29 13:59:44 +02:00
README.md Fix version 4 - link 2021-10-11 11:03:08 +02:00

misp-osint-collection

This repository describes a process/best-practices to gather OSINT information (such as public report, blog posts, twitter, information, notes) into a MISP event. The goal is to ensure that the majority of OSINT gathered information in MISP information sharing communities used similar techniques.

A process with best practices to add OSINT gathered information into MISP

The document is available in draw.io format and the source is available).

TODO

  • Add the steps in a simple JSON/Markdown (to generate the graph/mindmap from the text)
  • Add improved workflow taxonomy
  • Add the other source such as MISP information sharing communities where similar information can be found
  • Add the workflow in MISP core software

How to contribute?

Fork the project, download the drawio format document, edit the document with drawio, commit and do a pull-request.

License

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

Copyright (c) 2017-2019 Alexandre Dulaunoy
Copyright (c) 2019 Vincent Falconieri