-
Notifications
You must be signed in to change notification settings - Fork 639
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add PAP to case to indicate which kind of action is allowed #616
Comments
Hello @To-om, Is someone currently working on this feature? If I am not mistaken, this feature seems to already exist in TheHive when creating a new case. Please advise. Respectfully |
@AzureFlameGod this feature does not exist yet and will be implemented in 3.1. It must not be confounded with the TLP safeguards that analyzers implement (a.k.a While the colors in the PAP taxonomy are similar to those of the TLP, they serve a different purpose and are actions that will be applicable to actions you could or could not do during your incident response process depending on the stance you have defined wrt the threat actor you are dealing with. |
Request Type
Feature Request
Description
PAP (for Permissible Actions Protocol) aims to indicate to analyst the posture to adopt: how much we accept that the attacker detect the current analysis.
As for TLP, PAP is declined in 4 values:
Tasks
pap
attribute to case classpap
attribute to case template classThe text was updated successfully, but these errors were encountered: