Hello folks,
Has anyone of you made it work that you somehow update the sighting of an attribute in connected MISP instance?
I have my MISP integrated to Splunk, IoC are being downloaded to TI framework. Based on this some correlation searches that are scheduled, TI-based notables triggers
I am looking for a way how to get the feedback about TP/FP back to MISP.
I am using MISP42Splunk app, which has an adaptive response action "Alert for sighting MISP attribute(s)" but I cannot make it work.
I was also trying to do it via some in-build MISP command without any success.
Do you guy have implemented this feature of do you know some way to do it?
Thanks!
... View more