{"users":[{"id":4,"username":"adulau","name":"Alexandre Dulaunoy","avatar_template":"/user_avatar/discourse.ossbase.org/adulau/{size}/6_2.png","admin":true,"moderator":true,"trust_level":2},{"id":10,"username":"Rafiot","name":"Raphaël Vinot","avatar_template":"/user_avatar/discourse.ossbase.org/rafiot/{size}/24_2.png","trust_level":1},{"id":31,"username":"aaronkaplan","name":"AaronK","avatar_template":"/user_avatar/discourse.ossbase.org/aaronkaplan/{size}/69_2.png","trust_level":1},{"id":234,"username":"alexandercronin","name":"Alex Cronin","avatar_template":"/user_avatar/discourse.ossbase.org/alexandercronin/{size}/614_2.png","trust_level":0},{"id":15,"username":"wllm-rbnt","name":"","avatar_template":"/user_avatar/discourse.ossbase.org/wllm-rbnt/{size}/249_2.png","trust_level":2},{"id":95,"username":"claudex","name":"Claudex","avatar_template":"/user_avatar/discourse.ossbase.org/claudex/{size}/227_2.png","trust_level":1},{"id":222,"username":"rdmmf","name":"Thomas Caillet","avatar_template":"/user_avatar/discourse.ossbase.org/rdmmf/{size}/580_2.png","trust_level":0},{"id":22,"username":"CryptographySandbox","name":"Arash-AbstractionsLab","avatar_template":"/user_avatar/discourse.ossbase.org/cryptographysandbox/{size}/50_2.png","trust_level":1},{"id":224,"username":"gulsezim11","name":"Gulsezim Duisen","avatar_template":"/user_avatar/discourse.ossbase.org/gulsezim11/{size}/585_2.png","trust_level":0},{"id":27,"username":"ivazsndv","name":"Ivazsndv","avatar_template":"/user_avatar/discourse.ossbase.org/ivazsndv/{size}/59_2.png","trust_level":1},{"id":7,"username":"Terrtia","name":"Thirion Aurélien","avatar_template":"/user_avatar/discourse.ossbase.org/terrtia/{size}/18_2.png","admin":true,"moderator":true,"trust_level":1},{"id":221,"username":"lauraB","name":"Laurabernardy","avatar_template":"/user_avatar/discourse.ossbase.org/laurab/{size}/579_2.png","trust_level":0},{"id":12,"username":"iglocska","name":"Andras Iklody","avatar_template":"/user_avatar/discourse.ossbase.org/iglocska/{size}/26_2.png","trust_level":1},{"id":230,"username":"Tibso","name":"Tibso","avatar_template":"/user_avatar/discourse.ossbase.org/tibso/{size}/602_2.png","trust_level":0},{"id":231,"username":"KylVGoi","name":"Kyl V Goi","avatar_template":"/user_avatar/discourse.ossbase.org/kylvgoi/{size}/603_2.png","trust_level":0},{"id":23,"username":"ddurvaux","name":"David Durvaux","avatar_template":"/user_avatar/discourse.ossbase.org/ddurvaux/{size}/51_2.png","trust_level":1},{"id":229,"username":"dario-br","name":"Dario Br","avatar_template":"/user_avatar/discourse.ossbase.org/dario-br/{size}/594_2.png","trust_level":0},{"id":226,"username":"ajoga","name":"Aurélien Joga","avatar_template":"/user_avatar/discourse.ossbase.org/ajoga/{size}/587_2.png","trust_level":2},{"id":225,"username":"christianteuschel","name":"Christianteuschel","avatar_template":"/user_avatar/discourse.ossbase.org/christianteuschel/{size}/586_2.png","trust_level":0},{"id":220,"username":"matsdm","name":"Mats De Meyer","avatar_template":"/user_avatar/discourse.ossbase.org/matsdm/{size}/578_2.png","trust_level":0},{"id":20,"username":"qjerome","name":"Quentin JEROME","avatar_template":"/user_avatar/discourse.ossbase.org/qjerome/{size}/48_2.png","trust_level":1},{"id":8,"username":"righel","name":"Luciano Righetti","avatar_template":"/user_avatar/discourse.ossbase.org/righel/{size}/19_2.png","admin":true,"moderator":true,"trust_level":1},{"id":227,"username":"ecrou-exact","name":"GEFFE Théo","avatar_template":"/user_avatar/discourse.ossbase.org/ecrou-exact/{size}/592_2.png","trust_level":0},{"id":11,"username":"mokaddem","name":"Sami Mokaddem","avatar_template":"/user_avatar/discourse.ossbase.org/mokaddem/{size}/25_2.png","trust_level":1},{"id":5,"username":"cedric","name":"Cédric Bonhomme","avatar_template":"/user_avatar/discourse.ossbase.org/cedric/{size}/112_2.png","admin":true,"trust_level":2}],"primary_groups":[],"flair_groups":[],"topic_list":{"can_create_topic":false,"more_topics_url":"/c/hackathon-lu/5?page=1","per_page":30,"top_tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"},{"id":3,"name":"hackathon-2025","slug":"hackathon-2025"},{"id":1,"name":"misp","slug":"misp"},{"id":2,"name":"vulnerability-lookup","slug":"vulnerability-lookup"},{"id":49,"name":"misp-workbench","slug":"misp-workbench"},{"id":8,"name":"ai","slug":"ai"},{"id":50,"name":"ail-project","slug":"ail-project"},{"id":21,"name":"hacklu","slug":"hacklu"},{"id":35,"name":"rulezet","slug":"rulezet"}],"topics":[{"fancy_title":"About the hackathon.lu category","id":14,"title":"About the hackathon.lu category","slug":"about-the-hackathon-lu-category","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2025-03-20T12:37:44.388Z","last_posted_at":"2025-03-20T12:37:44.397Z","bumped":true,"bumped_at":"2025-04-09T08:53:31.804Z","archetype":"regular","unseen":false,"pinned":true,"unpinned":null,"excerpt":"This 2-day physical Hackathon, held in Luxembourg on April 14th and 15th, 2026, focuses on the development of free and open-source software for cybersecurity. We aim to convene diverse developer groups to collaborate on &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":37,"like_count":0,"has_summary":false,"last_poster_username":"adulau","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Remote headed captures with Xpra","id":1082,"title":"Remote headed captures with Xpra","slug":"remote-headed-captures-with-xpra","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-23T18:59:07.214Z","last_posted_at":"2026-04-23T18:59:07.339Z","bumped":true,"bumped_at":"2026-04-23T18:59:07.339Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Bypassing captchas has been a problem for a while and it is getting worse because almost all the phishing sites are hidden behind providers like Cloudflare. \nUntil now, the solution was to run the capture from a machine &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"},{"id":50,"name":"ail-project","slug":"ail-project"}],"tags_descriptions":{},"views":4,"like_count":1,"has_summary":false,"last_poster_username":"Rafiot","category_id":5,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":10,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Hackathon.lu 2026: a strong year for open cybersecurity collaboration","id":1081,"title":"Hackathon.lu 2026: a strong year for open cybersecurity collaboration","slug":"hackathon-lu-2026-a-strong-year-for-open-cybersecurity-collaboration","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/0c2f2513a4782cb7207597bda2d3ee8d76dae7a4_2_1024x576.jpeg","created_at":"2026-04-23T16:03:48.902Z","last_posted_at":"2026-04-23T16:03:49.090Z","bumped":true,"bumped_at":"2026-04-23T16:03:49.090Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Hackathon.lu 2026: a strong year for open cybersecurity collaboration\nHackathon.lu 2026, held in Luxembourg on 14–15 April 2026, once again showed what makes this event special: it is not just a place to present ideas, b&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":20,"like_count":1,"has_summary":false,"last_poster_username":"adulau","category_id":5,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Generic MISP AI Module - architecture considerations, second prototype implementation released","id":1077,"title":"Generic MISP AI Module - architecture considerations, second prototype implementation released","slug":"generic-misp-ai-module-architecture-considerations-second-prototype-implementation-released","posts_count":2,"reply_count":0,"highest_post_number":2,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/effb6780c690cd4018c9e8ca4501b84056733b99_2_1024x984.jpeg","created_at":"2026-04-15T19:34:49.089Z","last_posted_at":"2026-04-20T18:57:03.041Z","bumped":true,"bumped_at":"2026-04-20T18:57:03.041Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"AIPITCH\nTwo days of specification writing, discussions, architecture designs, writing down use-cases for one topic: combining LLMs and MISP. Where does it make sense? Which types of NLP tasks (use-case categories) would &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":1,"name":"misp","slug":"misp"},{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"},{"id":8,"name":"ai","slug":"ai"}],"tags_descriptions":{},"views":49,"like_count":2,"has_summary":false,"last_poster_username":"alexandercronin","category_id":5,"op_like_count":2,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":null,"description":"Original Poster","user_id":31,"primary_group_id":null,"flair_group_id":null},{"extras":"latest","description":"Most Recent Poster","user_id":234,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"SSLDump status update","id":1080,"title":"SSLDump status update","slug":"ssldump-status-update","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-17T14:34:19.649Z","last_posted_at":"2026-04-17T14:34:19.749Z","bumped":true,"bumped_at":"2026-04-17T14:34:19.749Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Hi, \nHere is the status summary of what was done regarding SSLDump during the Hackathon. \nDuring the first day, I presented a general status of the project during the short talk session. \nI tested a very simple patch tha&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":6,"like_count":1,"has_summary":false,"last_poster_username":"wllm-rbnt","category_id":5,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":15,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Create an kubernetes enrichment daemon for Kunai","id":1079,"title":"Create an kubernetes enrichment daemon for Kunai","slug":"create-an-kubernetes-enrichment-daemon-for-kunai","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/8317774dc17bdb09e01e36d748700241505692de_2_1024x512.png","created_at":"2026-04-17T14:02:39.236Z","last_posted_at":"2026-04-17T14:02:39.334Z","bumped":true,"bumped_at":"2026-04-17T14:02:39.334Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Following the test to run Kunai in kubernetes, it was found that Kunai have little information for the process inside the container. It decided to create a deamon that connect to the local CRI and extract the information&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":3,"like_count":0,"has_summary":false,"last_poster_username":"claudex","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":95,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Running Kunai in Kubernetes","id":1078,"title":"Running Kunai in Kubernetes","slug":"running-kunai-in-kubernetes","posts_count":2,"reply_count":0,"highest_post_number":2,"image_url":null,"created_at":"2026-04-17T13:55:13.368Z","last_posted_at":"2026-04-17T13:57:11.538Z","bumped":true,"bumped_at":"2026-04-17T13:57:11.538Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Find what options are required to run Kunai in kubernetes","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":5,"like_count":0,"has_summary":false,"last_poster_username":"claudex","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":95,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Release of BSimVis v0.1.0","id":1050,"title":"Release of BSimVis v0.1.0","slug":"release-of-bsimvis-v0-1-0","posts_count":2,"reply_count":0,"highest_post_number":2,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/b97edce7ab3fe81fca1275a8b2f85fa73d079903_2_1024x512.png","created_at":"2026-04-14T11:08:55.566Z","last_posted_at":"2026-04-17T09:46:57.636Z","bumped":true,"bumped_at":"2026-04-17T09:46:57.636Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"BSimVis is a tool to analyze similarities across a collection of binaries, based on Ghidra analyzers and the BSim (Behavioral Similarity) plugin. It allows further similarity analysis, function diffing, and family cluste&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":10,"like_count":2,"has_summary":false,"last_poster_username":"rdmmf","category_id":5,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":222,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"IDPS-ESCAPE v0.10, SATRAP-DL v0.5 and PyFlowintel v0.3","id":1054,"title":"IDPS-ESCAPE v0.10, SATRAP-DL v0.5 and PyFlowintel v0.3","slug":"idps-escape-v0-10-satrap-dl-v0-5-and-pyflowintel-v0-3","posts_count":6,"reply_count":2,"highest_post_number":6,"image_url":null,"created_at":"2026-04-14T13:15:42.327Z","last_posted_at":"2026-04-16T19:51:19.087Z","bumped":true,"bumped_at":"2026-04-16T19:51:19.087Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"IDPS-ESCAPE \nPreparing the next release of IDPS-ESCAPE, SATRAP-DL and PyFlowintel with @gulsezim11 and @ivazsndv \n\n Validation of one SONAR scenario (probably resource usage)\n Validation of RADAR support for low-friction&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":22,"like_count":5,"has_summary":false,"last_poster_username":"ivazsndv","category_id":5,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":null,"description":"Original Poster","user_id":22,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Frequent Poster","user_id":224,"primary_group_id":null,"flair_group_id":null},{"extras":"latest","description":"Most Recent Poster","user_id":27,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Location based document tagging","id":1055,"title":"Location based document tagging","slug":"location-based-document-tagging","posts_count":6,"reply_count":1,"highest_post_number":6,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/02b8bf5293940e3f789c64255d826f4e1b20ec4d_2_768x1024.jpeg","created_at":"2026-04-14T14:20:13.378Z","last_posted_at":"2026-04-16T10:02:50.295Z","bumped":true,"bumped_at":"2026-04-16T10:02:50.295Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Location based document tagging \n  \nThe issue is to find document mentioning location and especially vocabulary related to geolocation. \nThe discussions was around a fast way to lookup for location terminology and store &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"},{"id":50,"name":"ail-project","slug":"ail-project"}],"tags_descriptions":{},"views":26,"like_count":3,"has_summary":false,"last_poster_username":"adulau","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Frequent Poster","user_id":7,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Frequent Poster","user_id":221,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"MISP - Experimental integration of Pivotick","id":1076,"title":"MISP - Experimental integration of Pivotick","slug":"misp-experimental-integration-of-pivotick","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T16:08:10.714Z","last_posted_at":"2026-04-15T16:08:10.860Z","bumped":true,"bumped_at":"2026-04-15T16:08:10.860Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Replacement of the correlation graph in MISP with Sami Mokaddem’s brand new graph library, Pivotick. Only for the Overmind theme for now.","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":18,"like_count":0,"has_summary":false,"last_poster_username":"iglocska","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":12,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"DnsLiar - Implementing a whitelist","id":1075,"title":"DnsLiar - Implementing a whitelist","slug":"dnsliar-implementing-a-whitelist","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T15:57:31.691Z","last_posted_at":"2026-04-15T15:57:31.822Z","bumped":true,"bumped_at":"2026-04-15T15:57:31.822Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"DnsLiar is a DNS forwarder that uses a blacklist to block unwanted domains and IPs. Upon first initialization, it fetches a few million domains to feed its database so you can just start using it after a few minutes. My &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":20,"like_count":0,"has_summary":false,"last_poster_username":"Tibso","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":230,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Dnsliar - Vulnerability Assessment","id":1074,"title":"Dnsliar - Vulnerability Assessment","slug":"dnsliar-vulnerability-assessment","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T15:35:31.263Z","last_posted_at":"2026-04-15T15:35:31.376Z","bumped":true,"bumped_at":"2026-04-15T15:35:31.376Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"I did some Vulnerability Assessment on the tool Dnsliar. \nThe goal was to see if it is production ready and well optimized. \nI first did some fuzzing and try to stress the server. Using nmap script tool (dns-fuzz), Scapy&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":12,"like_count":0,"has_summary":false,"last_poster_username":"KylVGoi","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":231,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"MISP Engineering Bay v1.0 release","id":1072,"title":"MISP Engineering Bay v1.0 release","slug":"misp-engineering-bay-v1-0-release","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T15:12:55.416Z","last_posted_at":"2026-04-15T15:12:55.545Z","bumped":true,"bumped_at":"2026-04-15T15:12:55.545Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"MISP Engineering Bay is a collection of web-based authoring tools for the MISP threat intelligence sharing platform. It eliminates the need to manually craft and maintain the JSON files that define MISP’s core data struc&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":13,"like_count":1,"has_summary":false,"last_poster_username":"iglocska","category_id":5,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":12,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Sysdiagnose Analysis Framework (SAF)","id":1056,"title":"Sysdiagnose Analysis Framework (SAF)","slug":"sysdiagnose-analysis-framework-saf","posts_count":6,"reply_count":1,"highest_post_number":6,"image_url":null,"created_at":"2026-04-14T14:27:27.344Z","last_posted_at":"2026-04-15T14:58:42.107Z","bumped":true,"bumped_at":"2026-04-15T14:58:42.107Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Work on improvements for the framework \n\nfix use the IOService or IODeviceTree parser to get the data if remotectl_dumpstate is not available · Issue #162 · EC-DIGIT-CSIRC/sysdiagnose · GitHub (FIXED)","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":22,"like_count":1,"has_summary":false,"last_poster_username":"ddurvaux","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":23,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Frequent Poster","user_id":229,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Frequent Poster","user_id":226,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"MISP / AIL contribution tentative","id":1071,"title":"MISP / AIL contribution tentative","slug":"misp-ail-contribution-tentative","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T14:26:19.991Z","last_posted_at":"2026-04-15T14:26:20.162Z","bumped":true,"bumped_at":"2026-04-15T14:26:20.162Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Initially I wanted to fix this bug I reported few month ago: https://github.com/ail-project/ail-framework/issues/232 \nBeing on a different laptop (OpenSuse) &amp; not working with MISP since then, I had to go through the doc&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":15,"like_count":1,"has_summary":false,"last_poster_username":"ajoga","category_id":5,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":226,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Audio Assistant in MISP","id":1060,"title":"Audio Assistant in MISP","slug":"audio-assistant-in-misp","posts_count":3,"reply_count":0,"highest_post_number":3,"image_url":null,"created_at":"2026-04-15T11:33:44.549Z","last_posted_at":"2026-04-15T13:55:19.763Z","bumped":true,"bumped_at":"2026-04-15T13:55:19.763Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"The aim is to enhance the user experience of a MISP user with audio interaction. \nWhat user have I had in mind: \nA) Novice MISP user who is overwhelmed with the information presented. Reading is more cognitive demanding &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":22,"like_count":0,"has_summary":false,"last_poster_username":"christianteuschel","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":225,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"AIL - Migrate graph node to pivotik","id":1070,"title":"AIL - Migrate graph node to pivotik","slug":"ail-migrate-graph-node-to-pivotik","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T13:53:09.308Z","last_posted_at":"2026-04-15T13:53:09.401Z","bumped":true,"bumped_at":"2026-04-15T13:53:09.401Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Migrated AIL correlations and relationships graph to pivotik","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":10,"like_count":0,"has_summary":false,"last_poster_username":"Terrtia","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":7,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Privacy Enhancing Technologies in MISP Workflows","id":1069,"title":"Privacy Enhancing Technologies in MISP Workflows","slug":"privacy-enhancing-technologies-in-misp-workflows","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T13:43:25.114Z","last_posted_at":"2026-04-15T13:43:25.233Z","bumped":true,"bumped_at":"2026-04-15T13:43:25.233Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Description: \nAs an initial step to implement Privacy Enhancing Technologies (PETs) in MISP, we are starting with a Private Set Intersection (PSI) workflow. This allows for getting the intersection of event attributes on&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":1,"name":"misp","slug":"misp"},{"id":21,"name":"hacklu","slug":"hacklu"},{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":22,"like_count":3,"has_summary":false,"last_poster_username":"matsdm","category_id":5,"op_like_count":3,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":220,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Kunai’s Detection Capabilities: LinkPro eBPF Rootkit Analysis","id":1068,"title":"Kunai’s Detection Capabilities: LinkPro eBPF Rootkit Analysis","slug":"kunai-s-detection-capabilities-linkpro-ebpf-rootkit-analysis","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T13:37:00.878Z","last_posted_at":"2026-04-15T13:37:00.996Z","bumped":true,"bumped_at":"2026-04-15T13:37:00.996Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Description: \nA recent inquiry asked whether Kunai can detect the LinkPro eBPF rootkit, as detailed in Synacktiv’s analysis. We investigated Kunai’s sandbox and confirmed that the two samples mentioned in the article wer&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":7,"like_count":0,"has_summary":false,"last_poster_username":"qjerome","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":20,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"MISP Workbench - Hunts heatmap","id":1067,"title":"MISP Workbench - Hunts heatmap","slug":"misp-workbench-hunts-heatmap","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/8280b167bb00b05a136a25b923bf984b5e458e7a_2_1024x561.png","created_at":"2026-04-15T13:27:10.992Z","last_posted_at":"2026-04-15T13:27:11.117Z","bumped":true,"bumped_at":"2026-04-15T13:27:11.117Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"MISP Workbench hunts now include a heatmap view, giving you a visual overview of TTP coverage across your tracked hunts — making it easier to spot patterns and identify gaps in your detection landscape at a glance. \n  \nS&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"},{"id":49,"name":"misp-workbench","slug":"misp-workbench"}],"tags_descriptions":{},"views":6,"like_count":0,"has_summary":false,"last_poster_username":"righel","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":8,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"MISP Export: Rules &amp; Bundles as MISP Objects and Events (Rulezet)","id":1066,"title":"MISP Export: Rules & Bundles as MISP Objects and Events (Rulezet)","slug":"misp-export-rules-bundles-as-misp-objects-and-events-rulezet","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T13:24:49.019Z","last_posted_at":"2026-04-15T13:24:49.124Z","bumped":true,"bumped_at":"2026-04-15T13:24:49.124Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"MISP Export: Rules &amp; Bundles as MISP Objects and Events \nAdd the ability to export detection rules and bundles directly into the MISP ecosystem. \nA single rule could be exported as a MISP object (using a dedicated detect&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":1,"name":"misp","slug":"misp"},{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"},{"id":35,"name":"rulezet","slug":"rulezet"}],"tags_descriptions":{},"views":6,"like_count":0,"has_summary":false,"last_poster_username":"ecrou-exact","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":227,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"MISP Workbench - MITRE ATT&amp;CK Pattern Hunts","id":1065,"title":"MISP Workbench - MITRE ATT&CK Pattern Hunts","slug":"misp-workbench-mitre-att-ck-pattern-hunts","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/910894faa0e2499d24293b2c2cb0228782fa75b5_2_1024x728.png","created_at":"2026-04-15T13:21:28.776Z","last_posted_at":"2026-04-15T13:21:28.889Z","bumped":true,"bumped_at":"2026-04-15T13:21:28.889Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"MISP Workbench now supports MITRE ATT&amp;CK Pattern hunts! \nTrack one or more TTPs and receive instant alerts whenever a new attribute or event matches a tag from the MISP MITRE ATT&amp;CK Pattern Galaxy. \n  \nSee docs: \n\n\nSee P&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"},{"id":49,"name":"misp-workbench","slug":"misp-workbench"}],"tags_descriptions":{},"views":5,"like_count":0,"has_summary":false,"last_poster_username":"righel","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":8,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Pivotick: Improved UI &amp; Rendering","id":1064,"title":"Pivotick: Improved UI & Rendering","slug":"pivotick-improved-ui-rendering","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T13:20:35.727Z","last_posted_at":"2026-04-15T13:20:35.819Z","bumped":true,"bumped_at":"2026-04-15T13:20:35.819Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Added node labels with configurable options\nImproved interaction and features for the ego-graph for neighbor graph","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":12,"like_count":0,"has_summary":false,"last_poster_username":"mokaddem","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":11,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"MeluxiNa, clusters, jobs and all that stuff","id":1063,"title":"MeluxiNa, clusters, jobs and all that stuff","slug":"meluxina-clusters-jobs-and-all-that-stuff","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T13:20:13.801Z","last_posted_at":"2026-04-15T13:20:13.893Z","bumped":true,"bumped_at":"2026-04-15T13:20:13.893Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Managed to get access to Meluxina, the SLURM batch job system takes time to getting used to.  Trying to get axolotl.ai installed, but running out of disk space. Will try some more in the evening and report / share instru&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"},{"id":8,"name":"ai","slug":"ai"}],"tags_descriptions":{},"views":7,"like_count":0,"has_summary":false,"last_poster_username":"aaronkaplan","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":31,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Misp-module results in MISP Workflows","id":1062,"title":"Misp-module results in MISP Workflows","slug":"misp-module-results-in-misp-workflows","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T13:19:18.700Z","last_posted_at":"2026-04-15T13:19:18.835Z","bumped":true,"bumped_at":"2026-04-15T13:19:18.835Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Added support of results from misp-modules queries inside the workflow’s roaming data.\nAdded support of workflow environment variables for ad-hoc workflows.","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":12,"like_count":2,"has_summary":false,"last_poster_username":"mokaddem","category_id":5,"op_like_count":2,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":11,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Kunai - Dockerfile Simplified &amp; Container Size Reduced","id":1061,"title":"Kunai - Dockerfile Simplified & Container Size Reduced","slug":"kunai-dockerfile-simplified-container-size-reduced","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T12:35:58.309Z","last_posted_at":"2026-04-15T12:35:58.456Z","bumped":true,"bumped_at":"2026-04-15T12:35:58.456Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Description: \nThis update simplifies the Docker build process and reduces the container image size by adopting the official rust:latest base image. The changes maintain all required functionality while improving efficien&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":9,"like_count":1,"has_summary":false,"last_poster_username":"qjerome","category_id":5,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":20,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"EPSS importer (from official EPSS GitHub repository) for Vulnerability-Lookup","id":1059,"title":"EPSS importer (from official EPSS GitHub repository) for Vulnerability-Lookup","slug":"epss-importer-from-official-epss-github-repository-for-vulnerability-lookup","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T09:26:31.492Z","last_posted_at":"2026-04-15T09:26:31.658Z","bumped":true,"bumped_at":"2026-04-15T09:26:31.658Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"New feeder EPSSFeeder that fetches the latest daily EPSS CSV from the configured GitHub contents API, parses/decompresses it and stores per-CVE EPSS metadata under vulnerability meta keys (epss:&lt;meta_uuid&gt;), updating ind&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"},{"id":2,"name":"vulnerability-lookup","slug":"vulnerability-lookup"}],"tags_descriptions":{},"views":5,"like_count":0,"has_summary":false,"last_poster_username":"cedric","category_id":5,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":5,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Sighting tool for Tsunami","id":1058,"title":"Sighting tool for Tsunami","slug":"sighting-tool-for-tsunami","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-04-15T09:22:17.099Z","last_posted_at":"2026-04-15T09:22:17.210Z","bumped":true,"bumped_at":"2026-04-15T09:22:17.210Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"A client that extracts vulnerability-related observations from the Tsunami Security Scanner plugins \nrepository and publishes them as sightings on a Vulnerability-Lookup instance. \nEach committed Tsunami detector is a co&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"},{"id":2,"name":"vulnerability-lookup","slug":"vulnerability-lookup"}],"tags_descriptions":{},"views":5,"like_count":1,"has_summary":false,"last_poster_username":"cedric","category_id":5,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":5,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"User Interviews for CTI Folks - Participation is open, please reach out to us!","id":1053,"title":"User Interviews for CTI Folks - Participation is open, please reach out to us!","slug":"user-interviews-for-cti-folks-participation-is-open-please-reach-out-to-us","posts_count":2,"reply_count":0,"highest_post_number":2,"image_url":null,"created_at":"2026-04-14T12:49:15.428Z","last_posted_at":"2026-04-15T08:43:00.084Z","bumped":true,"bumped_at":"2026-04-15T08:43:00.084Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Hi everyone, \nWe’re Christian and Thomas, and we’re kicking off a series of short user interviews to better understand how you use MISP in practice. \nWhy are we doing this? \nWe want to identify and document real world us&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":1,"name":"misp","slug":"misp"},{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":25,"like_count":2,"has_summary":false,"last_poster_username":"christianteuschel","category_id":5,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":225,"primary_group_id":null,"flair_group_id":null}]}]}}