ivan ninichuck
Oct 21, 2020

I really believe that using these data objects is the key to connecting CTI to daily ops. Everything from training analyst what data sources to quickly reference when responding to an alert to advanced search capabilities. I’ll try to get my current thought explosion on paper so I can share the ideas. Fantastic work and great write up!!

ivan ninichuck
ivan ninichuck

Written by ivan ninichuck

Passionate about all things cyber security. Especially working with the Elastic Stack for Threat Hunting, MITRE ATT&CK and Sigma Rules.

Responses (1)