Open
Description
I don't know if this is reasonable, but it'd be really helpful if the intel portion could reach into a backend like CRITS via API. SCOT is a great start as an IR platform, but for larger uses, it's ideal to ingest a bunch of data into a better suited system like CRITS. I don't know how the current logic works, per se, but CRITS has a pretty extensive API. It also uses standard CybOX models for indicators.
Value to CRITS user: Allows integration with higher fidelity intel and integrate incident response team with threat intelligence team
How affects non-CRITS users: Doesn't affect at all. Existing simple intel function remains as-is.
Metadata
Metadata
Assignees
Labels
No labels