Hi,
We noticed today that the so-download-misp script is using wget.. this prevents the MISP API from being used and could be replaced with curl. That should allow for more flexibility instead of downloading all MISP rules in one large batch.
Is there a go-to method to exclude false positives from importing into SecurityOnion by using MISP’s Warning Lists by any chance?
Hi,
We noticed today that the so-download-misp script is using wget.. this prevents the MISP API from being used and could be replaced with curl. That should allow for more flexibility instead of downloading all MISP rules in one large batch.
Is there a go-to method to exclude false positives from importing into SecurityOnion by using MISP’s Warning Lists by any chance?