Scott J. Roberts
Scott J. Roberts
It turns out that the repo doesn't contain much in the way of documentation, so I think a prominent link to the docs would be awesome. Adding some examples wouldn't...
https://github.com/elastic/protections-artifacts
https://github.com/executemalware/Malware-IOCs
https://github.com/hvs-consulting/ioc_signatures
https://github.com/volexity/threat-intel
I've never added a service like ThreatView before. I have mixed feelings about it.
It would be great if there was a way to pull automated information for all extracted indicators. - VirusTotal - PassiveTotal - etc
The illustrious @stabbycutyou called out a cool idea that he implimented:  Having Cacador as a service could be really useful moving beyond a single system. I'd love to see...