Replies: 6 comments
-
At the moment there is no way except the JSON visualization. (Well there is the ElasticSearch integration with the Kibana GUI but I do not think this is what you are looking for because you would look at the data outside from the actual web application.) IntelOwl saves you the time to retrieve all these data from different sources/tools but then an analyst or an integration with a TIP (Threat Intel Platform) is required to sort out, aggregate and make sense of the data. I am interested in understanding what would you expect in terms of visualization. |
Beta Was this translation helpful? Give feedback.
-
Hi mlodic I think it would be a good idea to include the following, where possible:
Thanks for all! |
Beta Was this translation helpful? Give feedback.
-
thanks for the wishes! same to you! About your suggestions: 1- we have an opened issue regarding that (#732). We will implement this soon. I'll create some issues regarding these points. Thank you |
Beta Was this translation helpful? Give feedback.
-
EDIT: I have added point 2 that was only a draft |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
Thank you for your suggestion. Yeah, if I am correct that is a screen from Cortex. If I think about this specific example, it makes completely no sense to me. Only because there are records in AbuseIPDB would it mean that an observable is malicious? And if there are not is it safe? I mean, all threat analysts could agree that this is completely wrong and it is an over simplification of the problem. This is also dangerous because it could lead people to wrong conclusions. Understanding, analyzing, aggregating and evaluating the data is a really complex process that cannot be solved with just 2 lines of code. And it is extremely subjective to each one experience or use case. And yeah, right now IntelOwl is an "extractor" of data, not a real Threat Intelligence Platform. But we want it to become a TIP.
|
Beta Was this translation helpful? Give feedback.
-
Hello to all of you
I would like to ask if there is a way to visualize the data, provided by the different analyzers configured in InteOwl, in a more visual or comfortable way, that I don't know at the moment.
Thank you very much
Best regards!
Beta Was this translation helpful? Give feedback.
All reactions