opensearch-project / opensearch-project/security-analytics

[RFC] Integrate external Threat Intelligence vendor and enable users to do threat hunting using their feeds

Open
#989 0 comments 0 reactions 1 assignee View on GitHub

@eirsep is already working on this.

Since May 1, 2024.

enhancement v2.15.0
Dominant language
Java
Stars
111
Forks
111
Avg merge
1d 17h
Merged PRs (30d)
13

Description

Is your feature request related to a problem?
OpenSearch users are subscribing to third-party threat intelligence providers such as MISP, Anomali, Crowdstrike etc. to source Threat intelligence data. They are unable to leverage this data that they procure from vendors to do threat hunting for malicious IoC's on their data stored in OpenSearch.

OpenSearch Security Analytics has mechanism to scan user's ingested data for malicious IoC's by referring to threat intel IoC corpus already ingested in OpenSearch. Today Security Analytics is only integrated with a single opensource feed. Customers are looking for seamless integration with multiple third-party Threat Intel Platforms, pull in their feeds and provide a more comprehensive threat hunting, investigation and insights experience.

What solution would you like?
Build a TIP integration platform and start integrating with external TIPs via their SDK or API to pull in their threat intel feeds especially IoC data to start with.
Use the downloaded IoC data to enable user to perform threat hunting and report malicious IoC's in their data that match those from the feeds.

What alternatives have you considered?
Provide user with ability to upload custom feeds. that way user can download feeds from the

Do you have any additional context?
Add any other context or screenshots about the feature request here.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.