misp-book/sharing
Alexandre Dulaunoy a0fc8d6834 Typo fixed 2017-04-07 22:06:35 +02:00
..
figures first commit for the new part 2017-01-22 16:04:19 +01:00
README.md Typo fixed 2017-04-07 22:06:35 +02:00

README.md

Sharing / Synchronisation

  • Explanation

  • Setup

  • Roles

  • Tools

  • Server Settings

  • MISP's core functionality is sharing where everyone can be a consumer and/or a contributor/producer.

  • Quick benefit without the obligation to contribute

  • Low barrier access to get acquainted to the system

##Concept

Scenario example

##Setup

###Adding a server

Servers can be added by users via

https://<misp url>/servers/add

Add Server

The Add Server Form has several input fields:

Add Server

  1. Base URL

The base-url to the external server you want to sync with. Example: https://foo.sig.mil.be

  1. Instance Name

A name that will make it clear to your users what this instance is. For example: Organisation A's instance

  1. Remote Sync Organisation Type

The organization having the external server you want to sync with. Example: BE

  1. Local Organisation

  2. Authkey

You can find the authentication key on your profile on the external server.

  1. Push

Allow the upload of events and their attributes.

  1. Pull

Allow the download of events and their attributes from the server.

  1. Self Signed

Click this, if you would like to allow a connection despite the other instance using a self-signed certificate (not recommended). (server certificate file still needed)

  1. Server certificate file

You can also upload a certificate file if the instance you are trying to connect to has its own signing authority. (*.pem)

  1. Client certificate file

You can also upload a certificate file if the instance you are trying to connect to has its own signing authority. (*.pem)

###Test connection

Test connection can be used to test the connection to the remote server and will give a feedback about local and remote version of MISP.

###Rules

Rules are used to limit sharing to e.g. events with a given tag, or disabling sharing for events containing a certain Tag.

##Collaboration

Proposals

Forums / Threats

Forums can be used to discuss non event related topics.

Discussions can be accessed on the top "Global Actions - List Discussions"

and via URL:

https://<misp url>/threads/index

Discussions

####Create a new Topic

To create a new topic

https://<misp url>/posts/add

Start a topic

####Comment a topic

A topic can be commented by any user

https://<misp url>/threads/view/<topic id>

Comments to events

In MISP ongoing events can be commented by every user.

Contact reporter

Contact a reporter

This feature can be used to contact the person or the organisation that the person belongs to that has created the event.

All E-Mails can be enforced to be encrypted

Contact reporter

Receive alerts

It is possible to get alerts via encrypted mail in the following cases:

  • published events by other user of the MISP instance
  • events pushed to the MISP instance
  • events pulled by the MISP instance

These E-Mail alerts are an opt-in feature

Change user settings