[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: Re: [cti-stix] Question on Sightings Proposal and Cybox Observations
What do you think about using a low-confidence indicator for #1 and #2?
I also noticed that there’s a lot of workflow stuff in those use cases…implicit request from SOC to TI cell to do something, explicit request for sightings, explicit request to create an indicator, explicit +1 of indicator patterns (not necessarily a sighting
I assume?). A lot of that stuff is definitely not covered now.
From: <cti-stix@lists.oasis-open.org> on behalf of Jason Keirstead <Jason.Keirstead@ca.ibm.com>
Date: Monday, April 4, 2016 at 4:11 PM To: "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>, "cti-cybox@lists.oasis-open.org" <cti-cybox@lists.oasis-open.org> Subject: [cti-stix] Question on Sightings Proposal and Cybox Observations I have a cross-cutting STIX and Cybox question, and answering it on Slack seems too difficult (bouncing between too many channels). |
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]