Hello folks,
Has anyone of you made it work that you somehow update the sighting of an attribute in connected MISP instance?
I have my MISP integrated to Splunk, IoC are being downloaded to TI framework. Based on this some correlation searches that are scheduled, TI-based notables triggers
I am looking for a way how to get the feedback about TP/FP back to MISP.
I am using MISP42Splunk app, which has an adaptive response action "Alert for sighting MISP attribute(s)" but I cannot make it work.
I was also trying to do it via some in-build MISP command without any success.
Do you guy have implemented this feature of do you know some way to do it?
Thanks!
Never used this adaptive response type, did you get any success?