|
|
|
|
|
by iglocska
1581 days ago
|
|
Also, just to clarify: misp doesn’t and never has stored malware samples in the db. It was always password protected zip files, containing 2 files: a txt file with the original filename as well as the actual malware with its hash as the filename. |
|
I agree that the point of these tools is operationalizing CTI and the benefit of doing that with any tool exceeds not doing it. But ultimately my org has been much better off with custom management of our malware and then using OpenCTI to record CTI, and I think folks interested in MISP should check out OpenCTI as a possible alternative.