• Aucun résultat trouvé

MISP User Training - General usage of MISP MISP - Malware Information Sharing Platform & Threat Sharing

N/A
N/A
Protected

Academic year: 2022

Partager "MISP User Training - General usage of MISP MISP - Malware Information Sharing Platform & Threat Sharing"

Copied!
22
0
0

Texte intégral

(1)

MISP User Training - General usage of MISP

MISP - Malware Information Sharing Platform & Threat Sharing

Alexandre Dulaunoy Andras Iklody Rapha¨el Vinot TLP:WHITE

http://www.misp-project.org/

Twitter: @MISPProject

MISP Training @ Luxembourg 20180116

(2)

MISP - VM

Credentials

MISP admin: [email protected]/admin

SSH: misp/Password1234

Available at the following location (VirtualBox and VMWare):

https://www.circl.lu/misp-images/latest/

2 of 22

(3)

MISP - General Usage

Plan for this part of the training

Data model

Viewing data

Creating data

Co-operation

Distribution

Exports

3 of 22

(4)

MISP - Event (MISP’s basic building block)

4 of 22

(5)

MISP - Event (Attributes, giving meaning to events)

5 of 22

(6)

MISP - Event (Correlations on similar attributes)

6 of 22

(7)

MISP - Event (Proposals)

7 of 22

(8)

MISP - Event (Tags)

8 of 22

(9)

MISP - Event (Discussions)

9 of 22

(10)

MISP - Event (Taxonomies and proposal correlations)

10 of 22

(11)

MISP - Event (The state of the art MISP datamodel)

11 of 22

(12)

MISP - Viewing the Event Index

Event Index

Event context

Tags

Distribution

Correlations

Filters

12 of 22

(13)

MISP - Viewing an Event

Event View

Event context

Attributes

Category/type, IDS, Correlations

Objects

Galaxies

Proposals

Discussions

Tools to find what you are looking for

Correlation graphs

13 of 22

(14)

MISP - Creating and populating events in various ways (demo)

The main tools to populate an event

Adding attributes / batch add

Adding objects and how the object templates work

Freetext import

Import

Templates

Adding attachments / screenshots

API

14 of 22

(15)

MISP - Various features while adding data

What happens automatically when adding data?

Automatic correlation

Input modification via validation and filters (regex)

Tagging / Galaxy Clusters

Various ways to publish data

Publish with/without e-mail

Publishing via the API

Delegation

15 of 22

(16)

MISP - Using the data

Correlation graphs

Downloading the data in various formats

Cached exports

API (explained later)

Collaborating with users (proposals, discussions, emails)

16 of 22

(17)

MISP - Sync explained (if no admin training)

Sync connections

Pull/push model

Previewing instances

Filtering the sync

Connection test tool

Cherry pick mode

17 of 22

(18)

MISP - Feeds explained (if no admin training)

Feed types (MISP, Freetext, CSV)

Adding/editing feeds

Previewing feeds

Local vs Network feeds

18 of 22

(19)

MISP - Distributions explained

Your Organisation Only

This Community Only

Connected Communities

All Communities

Sharing Group

19 of 22

(20)

MISP - Distribution and Topology

20 of 22

(21)

MISP - Exports and API

Download an event

Quick glance at the APIs

Download search results

Cached exports

21 of 22

(22)

MISP - Shorthand admin (if no admin training)

Settings

Troubleshooting

Workers

Logs

22 of 22

Références

Documents relatifs

The data types are managed by attribute hubs which are logical ring structures, one per attribute in the schema. These attribute hubs, like Hname, Hsize and Htype in Figure 1,

Handling and sharing geospatial data from etherogeneous sources in a collaborative way can be addressed by a WebGIS platform, built with open source components.. An important role

The aim of a contam- ination between these systems and Semantic Web technologies is twofold: on one side, we think that the huge quantity of information created by the par-

• Sharing groups allow custom sharing (introduced in MISP 2.4) per event or even at attribute level.. ◦ Sharing communities can be used locally or even cross

• Even in a single organization, multiple use-cases of MISP can appear (groups using it for dynamic malware analysis correlations, dispatching notification). • In MISP 2.4.51,

• MISP 2 is a threat information sharing free & open source software. • There is a possibility to run it as a self-hosted service, or to join community

Sharing groups allow custom sharing (introduced in MISP 2.4) per event or even at attribute level. I Sharing communities can be used locally or even cross

( collaborative-intelligence ) and many other fields MISP taxonomies documentation is available 2 Review existing practices of tagging in your sharing community, reuse practices