diff --git a/x.17-eu-attack-community/content.tex b/x.17-eu-attack-community/content.tex index adc819e..2a4d830 100644 --- a/x.17-eu-attack-community/content.tex +++ b/x.17-eu-attack-community/content.tex @@ -5,6 +5,20 @@ \titlepage \end{frame} + +\begin{frame} + \frametitle{What is a MISP Galaxy?} + \begin{itemize} + \item MISP Galaxy is a feature in MISP and a MISP standard\footnote{\url{https://www.misp-standard.org/}} format to create {\bf contextualization libraries}. + \begin{itemize} + \item There are two main types: \textbf{combined list} or \textbf{matrix-like list}. + \end{itemize} + \item The first historical matrix-like galaxy was MITRE ATT\&CK\footnote{Presented at the first EU ATT\&CK community meeting in Luxembourg}. + \item Galaxies contain intelligence that can be \textbf{structured} in a matrix-like format. Relationships between models can be created, and implementation such as in MISP allows for the \textbf{forking and sharing of information}. This is typically attached to intelligence in threat intelligence platforms to add context. + \end{itemize} +\end{frame} + + \begin{frame} \frametitle{MISP galaxies over time} \begin{center} diff --git a/x.17-eu-attack-community/slide.pdf b/x.17-eu-attack-community/slide.pdf index b258c05..2765d17 100644 Binary files a/x.17-eu-attack-community/slide.pdf and b/x.17-eu-attack-community/slide.pdf differ