First things first, you'll need to grab them from my Github. Once you grab the .mtz file, you'll open up Maltego, and then click on Import, then Import Configuration ...
This repo is to demonstarte and explain how to automate threatfeed integration for Rapid7's InsightIDR (SIEM). InsightIDR natively does not support taxii-feeds(taxii-urls) in their product. That means ...
- Utilize SIEM tools like Splunk, AlienVault, QRadar, ArcSight, or similar to create new detection rules, correlation rules, etc. - Define use cases for playbooks and runbooks, and possess experience ...