ElasticIntel: Building an Open-Source Threat Intel Aggregation Platform - SANS CTI Summit 2018

Опубликовано: 20 Октябрь 2024
на канале: SANS Digital Forensics and Incident Response
6,003
82

In this talk we will present a new platform, built on Amazon Web Services and backed by ElasticSearch, that allows organizations to easily collect large amounts of open-source threat intelligence and make this data available for consumption by both analysts and machine-based tools via application programming interface (API). Orchestrated with Terraform, this platform can be spun up with a single command and be up and running in less than 30 minutes. No technical expertise is required. The goal of the platform is to provide an open-source alternative to expensive and often inflexible threat intelligence aggregation platforms. This will allow an organization to start using external threat intelligence without the high cost barrier to entry. Highly configurable and scalable from a few megabytes of data to many terabytes, the platform enables an organization to collect threat intel data from any number of sources. Sources can be easily configured by adding a few lines to a Json configuration file and data can be easily queried via the Kibana search interface or the query API, which can scale to tens of thousands of queries per second. We’ll also go over the reasons that prompted me to create this platform, the challenges I faced, the problems the platform solves, and the architecture behind it.

Finally, we’ll go over how to get started with the platform and how it can be easily integrated into an organization’s daily workflow.

Matt Jane (@PansyMcCoward), Principal Security Engineer, Okta