misp user training - general usage of misp - misp - threat ... · misp - various features while...

23
MISP User Training - General usage of MISP MISP - Threat Sharing Threat Sharing Team MISP Project http://www.misp-project.org/ Twitter: @MISPProject GSMA Edition

Upload: others

Post on 04-Aug-2020

17 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP User Training - General usage of MISPMISP - Threat Sharing

Threat Sharing

Team MISP Project

http://www.misp-project.org/Twitter: @MISPProject

GSMA Edition

Page 2: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - VM

CredentialsI MISP admin: [email protected]/adminI SSH: misp/Password1234

Available at the following location (VirtualBox and VMWare):I https://www.circl.lu/misp-images/latest/

1 22

Page 3: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - VM

It is a bit broken.I sudo -sI cd /var/www/MISP/I sudo pear installINSTALL/dependencies/Console_CommandLine/package.xml

I sudo pear installINSTALL/dependencies/Crypt_GPG/package.xml

I cd /usr/local/src/misp-modulesI pip3 install -r REQUIREMENTSI pip3 install .I reboot

2 22

Page 4: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - General Usage

Plan for this part of the trainingData modelViewing dataCreating dataCo-operationDistributionExports

3 22

Page 5: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Event (MISP’s basic building block)

4 22

Page 6: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Event (Attributes, giving meaning toevents)

5 22

Page 7: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Event (Correlations on similarattributes)

6 22

Page 8: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Event (Proposals)

7 22

Page 9: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Event (Tags)

8 22

Page 10: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Event (Discussions)

9 22

Page 11: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Event (Taxonomies and proposalcorrelations)

10 22

Page 12: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Event (The state of the art MISPdatamodel)

11 22

Page 13: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Viewing the Event Index

Event IndexI Event contextI TagsI DistributionI Correlations

Filters

12 22

Page 14: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Viewing an Event

Event ViewI Event contextI Attributes

Category/type, IDS, CorrelationsI ObjectsI GalaxiesI ProposalsI Discussions

Tools to �nd what you are looking forCorrelation graphs

13 22

Page 15: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Creating and populating events in variousways (demo)

The main tools to populate an eventI Adding attributes / batch addI Adding objects and how the object templates workI Freetext importI ImportI TemplatesI Adding attachments / screenshotsI API

14 22

Page 16: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Various features while adding data

What happens automatically when adding data?I Automatic correlationI Input modi�cation via validation and �lters (regex)I Tagging / Galaxy Clusters

Various ways to publish dataI Publish with/without e-mailI Publishing via the APII Delegation

15 22

Page 17: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Using the data

Correlation graphsDownloading the data in various formatsCached exportsAPI (explained later)Collaborating with users (proposals, discussions, emails)

16 22

Page 18: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Sync explained (if no admin training)

Sync connectionsPull/push modelPreviewing instancesFiltering the syncConnection test toolCherry pick mode

17 22

Page 19: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Feeds explained (if no admin training)

Feed types (MISP, Freetext, CSV)Adding/editing feedsPreviewing feedsLocal vs Network feeds

18 22

Page 20: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Distributions explained

Your Organisation OnlyThis Community OnlyConnected CommunitiesAll CommunitiesSharing Group

19 22

Page 21: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Distribution and Topology

20 22

Page 22: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Exports and API

Download an eventQuick glance at the APIsDownload search resultsCached exports

21 22

Page 23: MISP User Training - General usage of MISP - MISP - Threat ... · MISP - Various features while adding data What happens automatically when adding data? I Automatic correlation I

MISP - Shorthand admin (if no admin training)

SettingsTroubleshootingWorkersLogs

22 / 22