This repo is to demonstarte and explain how to automate threatfeed integration for Rapid7's InsightIDR (SIEM). InsightIDR natively does not support taxii-feeds(taxii-urls) in their product. That means ...
All four variants run from a single codebase — switch between them with one click via the header bar.
- Utilize SIEM tools like Splunk, AlienVault, QRadar, ArcSight, or similar to create new detection rules, correlation rules, etc. - Define use cases for playbooks and runbooks, and possess experience ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results