mirror of https://github.com/MISP/misp-training
chg:[attack] add an intro to MISP galaxy
parent
1ae215553d
commit
c289800fb9
|
@ -5,6 +5,20 @@
|
||||||
\titlepage
|
\titlepage
|
||||||
\end{frame}
|
\end{frame}
|
||||||
|
|
||||||
|
|
||||||
|
\begin{frame}
|
||||||
|
\frametitle{What is a MISP Galaxy?}
|
||||||
|
\begin{itemize}
|
||||||
|
\item MISP Galaxy is a feature in MISP and a MISP standard\footnote{\url{https://www.misp-standard.org/}} format to create {\bf contextualization libraries}.
|
||||||
|
\begin{itemize}
|
||||||
|
\item There are two main types: \textbf{combined list} or \textbf{matrix-like list}.
|
||||||
|
\end{itemize}
|
||||||
|
\item The first historical matrix-like galaxy was MITRE ATT\&CK\footnote{Presented at the first EU ATT\&CK community meeting in Luxembourg}.
|
||||||
|
\item Galaxies contain intelligence that can be \textbf{structured} in a matrix-like format. Relationships between models can be created, and implementation such as in MISP allows for the \textbf{forking and sharing of information}. This is typically attached to intelligence in threat intelligence platforms to add context.
|
||||||
|
\end{itemize}
|
||||||
|
\end{frame}
|
||||||
|
|
||||||
|
|
||||||
\begin{frame}
|
\begin{frame}
|
||||||
\frametitle{MISP galaxies over time}
|
\frametitle{MISP galaxies over time}
|
||||||
\begin{center}
|
\begin{center}
|
||||||
|
|
Binary file not shown.
Loading…
Reference in New Issue