Hello,
The last couple of days I`m enjoying myself with the minemeld engine and I find it astonishing. I managed to create dynamic feeds from RIPE archives for some geolocation EDLs, will soon post them by the way.
However, I would love to be able to define custom IOC types. For example - hash, filename, etc. This way much more information can be gathered and correlated to other types already present (e.g. url and domain).
Fiddling around the source, the only definition of these (types) I`ve found is in the json schema. So should defining the type just there would be sufficient? I guess not?
Can someone provide any guidelines or instructions on accomplishing this, if feasible at all?
Thanks,
Lyuben
... View more