MISP is becoming a popular open source option for managing threat intelligence at the operational level by sharing indicators of compromise (IOCs) and contextualizing them with other data. It can, however, be a bit daunting to figure out how to use the event filters. In this post I’ll go through...
[Read More]
Use Update Indicators API to push Threat Intelligence from MISP to Microsoft Sentinel
A quick intro on how to set up MISP, Azure Functions and Sentinel to push threat intelligence from MISP to Sentinel
An updated guidance on how to set up the MISP2Sentinel Azure Function to push threat intelligence from MISP to Microsoft Sentinel using the new Upload Indicators API.
[Read More]
Pushing Threat Intelligence from MISP to Microsoft Sentinel
A quick intro on how to set up MISP, Azure Functions and Sentinel to push threat intelligence from MISP to Sentinel
Background
[Read More]
Increasing the default timeout of Azure Functions
Azure Functions are used for most data connectors, but some of them have a very low default timeout.
Background
[Read More]
Removing orphaned Azure resource assigments
Simple fix for removing any "identity not found" on resources in Microsoft Azure.
Problem
[Read More]