LastInfosec Enrichment
コミュニティの提供による
Detection & Response Enablement
概要
Enriches file hashes and host observables in OpenCTI with LastInfoSec (Gatewatcher) threat feed data, providing enriched compromise evidence to accelerate threat analysis.
OpenCTI LastInfoSec connector will use the /v2/stix21/search_hash/{hash} and /v2/stix21/search_host/{host} API. Requirement : if you want to use LastInfoSec's intelligence, you need an API key. You could contact LastInfoSec's team here https://info.gatewatcher.com/en/lp/opencti LastInfosec has been acquired by Gatewatcher. LastInfoSec's Threat Feed is a data feed that makes it easier to detect threats within the information system. It contains enriched compromised evidences in order to reduce the time of threat analysis once detected.https://www.gatewatcher.com/en/our-solutions/lastinfosec/