December 15, 2022
MISP Training Video December Edition - Workflow
MISP has been a widely used open source CTI platform for the past decade, with a long list of tools that allow users to customise the data models and contextualisation of the platform, yet true customisation of the actual workflows and processes had to be done externally using custom scripts.
With the introduction of MISP workflows, this has changed and the workshop aims to walk the audience through some of the potential ideas of how one could adapt the tool to their own CSIRT’s or SOC’s workflows by using some useful examples during the session.
Content of Training Session
Resources
Cheatsheets
- Cheatsheet: Concepts & Data model
- Synchronisation logic
- Authentication logic
- For your lawyers or if you yourself are interested in the legal docs: MISP legal compliance (such as GDPR and alike)
Training materials
- Virtual machines (VirtualBox and VMWare format): https://vm.misp-project.org/
- All Slide Decks (source file and compiled): https://github.com/MISP/misp-training
- PyMISP: https://github.com/MISP/PyMISP/
- OpenAPI documentation: https://www.misp-project.org/documentation/openapi.html
- misp-stix a generic library for MISP standard format to STIX (1.1, 1.2, 2.0 and 2.1): documentation
Other ressources
- MISP Mastodon - @misp@misp-community.org
- MISP Twitter - Follow to get latest news
- Gitter MISP Support chat
- Benefits of running your own MISP instance
Acknowledgement
A huge thanks to all the participants for their active participation. The training is also part of the MeliCERTes project.