Quering DShield from Cortex, (Tue, Nov 20th)

Cortex is a tool part of the TheHive project[1]. As stated on the website, it is a “Powerful Observable Analysis Engine”. Cortex can analyze observables like IP addresses, emails, hashes, filenames against a huge (and growing) list of online services. I like the naming convention used by Cortex. We have “observables” that can be switched later to an “IOC” later if they are really relevant for us. Keep in mind that an interesting IOC for you could be totally irrelevant in another environment.

Article Link: https://isc.sans.edu/diary/rss/24330