Hi everyone, I decided to re-animate my old project: to fix threat intelligence for vulnerability management. First of all, why is it broken? (a picture attached) because today's threat intel is massively based on attack events, which means you get it too late. My idea is to create and maintain a database of available exploit capabilities, which whould help you to know (hopefully slightly in advance) what you need to urgently patch right now. https://uisgcon.org/pdf/uisgcon13-alex-smirnoff+what-is-wrong-with-informati... sildes 23-46 contain a more precise description of how would it look like. Yet I cannot do it by myself: i need either people to help me, or money to hire people, hosting resources, or probably all of the above. Anyone could suggest me a good direction to look for?
participants (1)
-
Alex Smirnoff