Introduction to NoiseRecon
Welcome to the intro guide to NoiseRecon! This guide is the best place to start with NoiseRecon. We cover what NoiseRecon is, what problems it can solve, and what are the main features.
If you are familiar with what NoiseRecon is, the documentation has a better reference on the internals and complete available features.
What is NoiseRecon?
NoiseRecon is threat intelligence aggregator and analysis engine.
NoiseRecon can ingest several data sources:
- IP address lists
- URL or domain lists
- email address lists
- Twitter data
- JSON
- manual entries
Usually the threat data is available, but often it is in a different format or with different semantics than the ones supported by internal applications. Or, there are systems that have threat data, and all it takes is to extract it from that system.
NoiseRecon offers a unified way to pull information from various sources and various formats, into a single repository.
From this repository, data can be exported in multiple formats or processed via the web gui.
An API interface is also available to provide easy integration with other systems or scripts.
Key features
The elements that set NoiseRecon appart from other threat intelligence services are:
Multi-input and multi-output - access to the data is done via a web interface or programatically, to allow others to integrate. We offer a series of out-of-the-box solutions, but these can be extended to include other systems.
Firewall and security tool agnostic - create a threat intelligence list end export it to your prefered security tool. We support most major firewall manufactures and SIEM products.
Source templates - take advantage of default sources and default templates to get you started quickly.
Next steps
See the page of NoiseRecon use cases to see the multiple ways NoiseRecon can be used.
Then seehow NoiseRecon compares to other threat intelligence to see how it fits into your existing infrastructure.
Finally, continue onwards with the getting started guide to use NoiseRecon to get real time threat intelligence.