Go to file
Sami Mokaddem 85f0f887d0
chg: [a.12-workflows] Updated slides to reflect the current design
2022-07-07 15:45:58 +02:00
0-intro-shorter chg: [notes] notes example 2022-02-09 15:59:12 +01:00
0-misp-introduction-to-information-sharing
1-misp-usage
1.1-misp-viper-integration
1.2-misp-integration
1.2.1-misp-integration-mail2misp
2-misp-administration
3-misp-taxonomy-tagging
3.1-misp-modules
3.2-misp-galaxy
3.3-misp-object-template
4-misp-standard
6.0-misp-dashboard
20200623-NATO-MUG-update
20200923-BNLSec
20200924-TW
20201027-ITBN-communities
20201203-NATO-MUG-update
20210902-NATO-MUG-update chg: wip 2021-09-02 11:28:59 +02:00
20211118-NATO-MUG-update fix: based on @jl's comments 2021-11-18 09:38:09 +01:00
AUSCERT2020
a.0-contributing
a.1-devintro
a.2-pymisp
a.3-misp-feed
a.4-best-practices
a.5-bis-decaying-indicators-light-version
a.5-decaying-indicators
a.6-forensic
a.7-rest-API add: postman training collection with basic endpoints 2021-11-23 14:59:34 +01:00
a.8-dev-hands-on
a.9-restsearch-dev
a.10-galaxy-2.0
a.11-misp-data-model chg: [data-model] Included usecase and purpose on each data model 2022-02-10 16:27:31 +01:00
a.12-misp-workflows chg: [a.12-workflows] Updated slides to reflect the current design 2022-07-07 15:45:58 +02:00
a.a-widget-dev
a.b-cli
a.c-deployment
a.d-community-and-cerebrate new: [community] joint community basics + melicertes deck added 2022-02-23 13:19:49 +01:00
attack
attack-2020
b.1-best-practices-in-threat-intelligence
b.2-turning-data-into-actionable-intelligence
b.4-turning-data-into-actionable-intelligence-short
b.5-turning-data-into-actionable-intelligence-training chg: [b.5] title renamed 2022-02-09 14:56:38 +01:00
b.5-turning-data-into-actionable-training
cheatsheets new: [cheatsheet] Added full event example 2022-02-10 15:45:15 +01:00
complementary/ack
events/20220602-EU-ATTACK chg: [EU-ATTACK] intro slide 2022-06-02 06:46:12 +02:00
exercises Summary 2021-06-12 01:44:37 +02:00
includes chg: [FIRST] update 2021-12-09 11:22:33 +01:00
mii.0-security
misp-summit Add files via upload 2021-10-27 09:04:51 +02:00
misp-summit-2019
output
themes
training-support chg: [sample] dirty harry added 2022-04-29 13:28:48 +02:00
x.1-belgomisp
x.2-melicertes
x.3-into-short
x.4-cansecwest
x.4-sharing-going-wild
x.5-covid
x.6-how-information-sharing-is-saving-us
x.6-isac-intro
x.8-first-cti-virtual
x.9-covid chg: [covid] uni.lu presentation 2021-06-07 09:06:57 +02:00
x.9-eu-attack-community
x.10-pisax.org
x.11-gsma chg: [doc] Added dependencies to doc 2022-05-20 17:26:50 +02:00
x.12-covid-recap
x.13-interpol
x.14-covid-first some fixes 2021-06-07 13:07:10 +02:00
x.15-subtitles Completed the subtitles for MISP General Usage Training Part 1 of 2 2022-02-07 00:25:12 +08:00
InterNews.tar.gz
README.md chg: [doc] Added dependencies to doc 2022-05-20 17:26:50 +02:00
build.sh chg: [build] make handout version of MISP training slides to allow the trainers 2022-02-10 10:39:57 +01:00
misp-training.pdf
sunet.tar.gz
table.md chg: [updated table] 2022-06-01 10:52:02 +02:00
table2.md

README.md

MISP Training Materials

This repository includes all the training materials in use such as

  • Core MISP (software and standard) trainings
  • Threat intelligence and OSINT training
  • Building information sharing communities workshop

All the materials are available with the complete LaTeX source code meant to assist in contributing or extending the training materials. A special attention is given to the open source licensing given to the materials. We welcome contributions in order to improve the training set for threat intelligence, intelligence gathering and analysis along with specific aspects of information sharing/exchange in information and national security.

Materials

Slides (PDF) Source Code
0-misp-introduction-to-information-sharing source
1-misp-usage source
1.2-misp-integration source
1.1-misp-viper-integration source
1.2.1-misp-integration-mail2misp source
2-misp-administration source
3-misp-taxonomy-tagging source
3.1-misp-modules source
3.2-misp-galaxy source
3.3-misp-object-template source
6.0-misp-dashboard source
a.0-contributing source
a.1-devintro source
a.2-pymisp source
a.3-misp-feed source
a.4-best-practices source
a.5-decaying-indicators source
a.5-bis-decaying-indicators-light-version source
a.6-forensic source
a.7-rest-API source
b.1-best-practices-in-threat-intelligence source
b.5-turning-data-into-actionable-intelligence-training source
a.8-dev-hands-on source
a.9-restsearch-dev source
a.10-galaxy-2.0 source
a.11-misp-data-model source
a.a-widget-dev source
b.2-turning-data-into-actionable-intelligence source
4-misp-standard source
x.13-exercise-movie source
a.b-cli source
a.c-deployment source

Complementary materials

Slides (PDF) Source Code
complete slide desk in one PDF source
MISP training cheat-sheet source
MISP feature list (for the trainers) source

Additional documentation

MISP Training videos

Sample videos which can be used to understand how the training materials are used in companion with a live MISP demo instance.

Passive DNS and MISP - Training videos

MISP Training support videos

Those are videos to support MISP trainings or demonstrations at large:

MISP Training VMs

Pre-built MISP training VMs are available at https://vm.misp-project.org/.

Source Code

The full source code of the training slide decks are available. You'll need to have an operating system with a recent installation of LaTeX including latex-beamer to work with them.

To build the complete set of training materials:

bash build.sh

The output directory will contain all the generated PDF files and the PDF file called misp-training.pdf which is the complete handout of all the slides.

Note: In case the rendering is somewhat broken, it might be related to latex using the styles installed systemwide in /usr/share/texlive/texmf-dist/tex/latex/beamertheme-focus. Removing this directory will solve the problem.

Dependencies

FiraMath Font

XeLaTex, can be parametered in .tex header (works in TeXshop):

% !TEX TS-program = xelatex
% !TEX encoding = UTF-8 Unicode

License, Attribution and Funding

All the materials are dual-licensed under GNU Affero General Public License version 3 or later and the Creative Commons Attribution-ShareAlike 4.0 International. You can use either one of the licenses depending of your use case of the training materials.

The MISP project training materials are co-financed and supported by CIRCL Computer Incident Response Center Luxembourg and co-financed by a CEF (Connecting Europe Facility) funding under CEF-TC-2016-3 - Cyber Security as Improving MISP as building blocks for next-generation information sharing.

All the source code is available at https://www.github.com/MISP/misp-training.

If you reuse the training materials, don't forget to include the above for attribution.

Contributors in alphabetical order

  • Steve Clement 🏠
  • Alexandre Dulaunoy 🏠
  • Andras Iklody 🏠
  • Sami Mokaddem 🏠
  • Sascha Rommelfangen 🏠
  • Christian Studer 🏠
  • Raphaël Vinot 🏠
  • Gerard Wagener 🏠