Solved

Threat Intelligence

  • 4 May 2021
  • 1 reply
  • 129 views

Userlevel 2
Badge +3

Which threat intelligence source should i use and what happens if i use multiple threat intelligence sources.

icon

Best answer by Basudev Raut 4 May 2021, 06:45

View original

1 reply

Userlevel 3
Badge +7

Hi Rupsan,

You can use multiple Threat Feeds in LogPoint, either Open Source (like MISP or a TAXII feed) or Proprietary (such as RecordedFuture, ProofPoint, CSIS). When you use multiple threat feeds,  fields like the source_ip or destination_ip from your sources may find a match with one or the other threat feeds and get enriched. 

However, it is advised to use few feeds that you are very fond of since such feeds add some performanceoverhead while fetching data. You may look into the data from table threat_intelligence and decide which feed provide you the most value and decide accordingly.

 

Reply