Skip to content

Set tags within Source as well as Operator [MISP] #103

@RatherBland

Description

@RatherBland

The current system of setting hardcoded tags is insufficient when ingesting from variable sources such as Twitter or RSS feeds.

I propose setting tags within the source as well as the operator. This allows for both default tags assigned to all ingested events, as well as tags set specifically for the source.

A great example of this providing value is using a Twitter source to search for emotet and another searching for njrat. Separately tagging these events would significantly improve the intelligence value for operators instead of just generic OSINT or MALWARE tags.

I will investigate the viability of this, but any suggestions would be appreciated.

Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions