\item{\bf Share analyses and reports} of digital forensic evidences.
\item{\bf Propose changes} to existing analyses or reports.
\item Extending existing events with additional evidences for local or use in limited distribution sharing (sharing can be defined at event level or attribute level).
\item{\bf Evaluate correlations}\footnote{MISP has a flexible correlation engine which can correlate on 1-to-1 value matches, but also on fuzzy hashing (e.g. ssdeep) or CIDR block matching.} of evidences against external or local attributes.
\item{\bf Report sightings} such as false-positive or true-positive (e.g. a partner/analyst has seen a similar indicator).
\end{itemize}
\end{frame}
\begin{frame}
\frametitle{Benefits of using MISP}
\begin{itemize}
\item LE can leverage the long-standing experience in information sharing and {\bf bridge their use-cases} with MISP's information sharing mechanisms.
\item{\bf Accessing existing MISP information sharing communities} by receiving actionable information from CSIRT/CERT networks or security researchers.
\item{\bf Bridging LE communities with other communities}. Sharing groups can be created (and managed) cross-sectors to support specific use-cases.
\item The {\bf MISP standard} is a flexible format which can be extended by users using the MISP platform. A MISP object template can be created in under 30 minutes, allowing users to rapidly share information using their own data-models with existing communities.
\end{itemize}
\end{frame}
\begin{frame}
\frametitle{Challenges and implementations}
\begin{itemize}
\item Standard sharing mechanism for forensic cases
\begin{itemize}
\item MISP allows for the efficient \textbf{collaborative} analysis of digital evidences
\item Correlation on certain attributes
\end{itemize}
\item Importing disk images and file system data activity (\texttt{Mactime})
\begin{itemize}
\item Development of an adaptable import tool: From Mactime to MISP \texttt{Mactime object}
\end{itemize}
\item Create, modify and visualise the timeline of events
\begin{itemize}
\item Development of a flexible timeline system at the event level