mirror of https://github.com/MISP/misp-training
chg:[attack] add an intro to MISP galaxy
parent
1ae215553d
commit
c289800fb9
|
@ -5,6 +5,20 @@
|
|||
\titlepage
|
||||
\end{frame}
|
||||
|
||||
|
||||
\begin{frame}
|
||||
\frametitle{What is a MISP Galaxy?}
|
||||
\begin{itemize}
|
||||
\item MISP Galaxy is a feature in MISP and a MISP standard\footnote{\url{https://www.misp-standard.org/}} format to create {\bf contextualization libraries}.
|
||||
\begin{itemize}
|
||||
\item There are two main types: \textbf{combined list} or \textbf{matrix-like list}.
|
||||
\end{itemize}
|
||||
\item The first historical matrix-like galaxy was MITRE ATT\&CK\footnote{Presented at the first EU ATT\&CK community meeting in Luxembourg}.
|
||||
\item Galaxies contain intelligence that can be \textbf{structured} in a matrix-like format. Relationships between models can be created, and implementation such as in MISP allows for the \textbf{forking and sharing of information}. This is typically attached to intelligence in threat intelligence platforms to add context.
|
||||
\end{itemize}
|
||||
\end{frame}
|
||||
|
||||
|
||||
\begin{frame}
|
||||
\frametitle{MISP galaxies over time}
|
||||
\begin{center}
|
||||
|
|
Binary file not shown.
Loading…
Reference in New Issue