A full walkthrough of the daily threat briefing workflow, from source event triage to publishing, showing how zsazsa turns scraper events into a finished briefing without switching between tools. Published on the MISP project website.
An article that describes how to manage recurring indicator feeds for your SOC and CSIRT. Instead of having multiple Python scripts creating export lists, use zsazsa as the central feed engine.
A second article is in draft going deeper into the workflow on how to create a vulnerability advisory.
Stay updated. Project changes, issues and discussions are on
GitHub. Watch the repository to be notified when a new release is published.