Hi all!
First, thank you so much for your awesome work on Aleph!
I am working with multiple large NGOs on building a user friendly Digital Forensic, Incident Response and OSINT investigation platform. Instead of starting from scratch I had a look to Aleph and to the FTM model. Aleph architecture looks very flexible. So, I wonder how complicated it would be for me to:
- manage new entities such as Threat actor, Campaign, Sample, etc.
- enrich these entities with information coming from various external sources such as RiskIQ, Virus Total, etc.
I know that many different IR, OSINT platforms/tools already exist but none of them manage large bunch of entities. Some of these tools focus on network indicators, others on APT, others on OSINT. As an example, I need to allow users to correlate malware campaigns with online misinformation campaigns, to correlate threat actors activities with security incident.
I looked at your documentation, I looked at how Aleph is constructed and it seems to me that extending Aleph would be the best way for me to build the tools the NGOs I work with need.
I apologize if opening an issue here was not the most appropriate way to reach out to you.
My best,
Esther
Hi all!
First, thank you so much for your awesome work on Aleph!
I am working with multiple large NGOs on building a user friendly Digital Forensic, Incident Response and OSINT investigation platform. Instead of starting from scratch I had a look to Aleph and to the FTM model. Aleph architecture looks very flexible. So, I wonder how complicated it would be for me to:
I know that many different IR, OSINT platforms/tools already exist but none of them manage large bunch of entities. Some of these tools focus on network indicators, others on APT, others on OSINT. As an example, I need to allow users to correlate malware campaigns with online misinformation campaigns, to correlate threat actors activities with security incident.
I looked at your documentation, I looked at how Aleph is constructed and it seems to me that extending Aleph would be the best way for me to build the tools the NGOs I work with need.
I apologize if opening an issue here was not the most appropriate way to reach out to you.
My best,
Esther