diff --git a/_posts/2016-07-22-MISP-2.4.49-released.md b/content/blog/2016-07-22-MISP-2.4.49-released.md similarity index 91% rename from _posts/2016-07-22-MISP-2.4.49-released.md rename to content/blog/2016-07-22-MISP-2.4.49-released.md index c55db4b..82583e2 100755 --- a/_posts/2016-07-22-MISP-2.4.49-released.md +++ b/content/blog/2016-07-22-MISP-2.4.49-released.md @@ -1,6 +1,7 @@ --- title: MISP 2.4.49 released with many improvements and fixes -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png +date: 2016-07-22 layout: post --- diff --git a/_posts/2016-08-01-MISP-1st-Hackathon.md b/content/blog/2016-08-01-MISP-1st-Hackathon.md similarity index 98% rename from _posts/2016-08-01-MISP-1st-Hackathon.md rename to content/blog/2016-08-01-MISP-1st-Hackathon.md index 9f3fa17..0d400c8 100755 --- a/_posts/2016-08-01-MISP-1st-Hackathon.md +++ b/content/blog/2016-08-01-MISP-1st-Hackathon.md @@ -1,6 +1,7 @@ --- title: MISP Hackathon 2016 -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png +date: 2016-08-01 layout: post --- diff --git a/_posts/2016-08-10-MISP-2.4.50-released.md b/content/blog/2016-08-10-MISP-2.4.50-released.md similarity index 94% rename from _posts/2016-08-10-MISP-2.4.50-released.md rename to content/blog/2016-08-10-MISP-2.4.50-released.md index dbb13f8..989232a 100755 --- a/_posts/2016-08-10-MISP-2.4.50-released.md +++ b/content/blog/2016-08-10-MISP-2.4.50-released.md @@ -1,6 +1,7 @@ --- title: MISP 2.4.50 released including new features, security and bug fixes. -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png +date: 2016-08-10 layout: post --- diff --git a/_posts/2016-08-11-MISP-Training-in-Brussels.md b/content/blog/2016-08-11-MISP-Training-in-Brussels.md similarity index 98% rename from _posts/2016-08-11-MISP-Training-in-Brussels.md rename to content/blog/2016-08-11-MISP-Training-in-Brussels.md index 47804d1..ec8134e 100755 --- a/_posts/2016-08-11-MISP-Training-in-Brussels.md +++ b/content/blog/2016-08-11-MISP-Training-in-Brussels.md @@ -1,7 +1,8 @@ --- title: MISP training, “the Brussels Edition”, CIRCL in collaboration with CERT.EU - September 5th 2016 +date: 2016-08-11 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- On September 5th 2016 and after 3 successful editions, the MISP (Malware Information and Threat Sharing Platform) training is traveling to Brussels. This workshop is organized by [CIRCL](https://www.circl.lu/) in collaboration with [CERT-EU](https://cert.europa.eu) and will take place at the European Economic and Social Committee’s premises. diff --git a/_posts/2016-08-12-Building-an-OCR-import-module-in-MISP.md b/content/blog/2016-08-12-Building-an-OCR-import-module-in-MISP.md similarity index 91% rename from _posts/2016-08-12-Building-an-OCR-import-module-in-MISP.md rename to content/blog/2016-08-12-Building-an-OCR-import-module-in-MISP.md index 99a9569..5650be5 100755 --- a/_posts/2016-08-12-Building-an-OCR-import-module-in-MISP.md +++ b/content/blog/2016-08-12-Building-an-OCR-import-module-in-MISP.md @@ -1,6 +1,7 @@ --- title: Building an OCR import module in MISP -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png +date: 2016-08-12 layout: post --- @@ -79,9 +80,9 @@ The module is automatically integrated in MISP via the [misp-modules framework]( An analyst will have access to the following MISP user-interfaces while using the OCR module. The module just work like an expansion module and the user will see all the potential indicators scanned from the document. The OCR module is included as an example in the misp-modules framework and can be directly enabled in the MISP configuration. In order to use the module, the [Tesseract OCR](http://miphol.com/muse/2013/05/install-tesseract-ocr-on-ubunt.html) have to be installed locally on your MISP instance. -![MISP user interface listing the modules and showing the ocr module](/assets/images/misp/blog/ocr1.png){:class="img-responsive"} +![MISP user interface listing the modules and showing the ocr module](/img/blog/ocr1.png){:class="img-responsive"} -![MISP ocr module - scan a file](/assets/images/misp/blog/ocr2.png){:class="img-responsive"} +![MISP ocr module - scan a file](/img/blog/ocr2.png){:class="img-responsive"} -![MISP ocr module - import scanned results](/assets/images/misp/blog/ocr3.png){:class="img-responsive"} +![MISP ocr module - import scanned results](/img/blog/ocr3.png){:class="img-responsive"} diff --git a/_posts/2016-08-29-MISP-2.4.51-released.md b/content/blog/2016-08-29-MISP-2.4.51-released.md similarity index 95% rename from _posts/2016-08-29-MISP-2.4.51-released.md rename to content/blog/2016-08-29-MISP-2.4.51-released.md index c832946..d7f0ffe 100755 --- a/_posts/2016-08-29-MISP-2.4.51-released.md +++ b/content/blog/2016-08-29-MISP-2.4.51-released.md @@ -1,6 +1,7 @@ --- title: MISP 2.4.51 released including new features and many bug fixes. -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png +date: 2016-08-29 layout: post --- diff --git a/_posts/2016-10-02-MISP-Upcoming-Activities.md b/content/blog/2016-10-02-MISP-Upcoming-Activities.md similarity index 97% rename from _posts/2016-10-02-MISP-Upcoming-Activities.md rename to content/blog/2016-10-02-MISP-Upcoming-Activities.md index 777bd60..2dc0172 100755 --- a/_posts/2016-10-02-MISP-Upcoming-Activities.md +++ b/content/blog/2016-10-02-MISP-Upcoming-Activities.md @@ -1,7 +1,8 @@ --- title: MISP Upcoming Activities in October and November 2016 +date: 2016-10-02 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- The next months for the MISP core team, it is full of interesting activities and upcoming events. diff --git a/_posts/2016-10-07-MISP-2.4.52-released.md b/content/blog/2016-10-07-MISP-2.4.52-released.md similarity index 93% rename from _posts/2016-10-07-MISP-2.4.52-released.md rename to content/blog/2016-10-07-MISP-2.4.52-released.md index 19ad184..825bc84 100755 --- a/_posts/2016-10-07-MISP-2.4.52-released.md +++ b/content/blog/2016-10-07-MISP-2.4.52-released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.52 released including new features and major improvements +date: 2016-10-07 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- We are glad to announce MISP 2.4.52 including new features, improvements and bug fixes. @@ -10,7 +11,7 @@ The following new features were introduced: - Freetext feed import: a flexible scheme to import any feed available on Internet and incorporate them automatically in MISP. The feed imported can create new event or update an existing event. The freetext feed feature permits to preview the import and quickly integrates external sources. -![External feed in MISP - an example of external feed configured](/assets/images/misp/freetext-feed.png){:class="img-responsive"} +![External feed in MISP - an example of external feed configured](/img/blog/misp/freetext-feed.png){:class="img-responsive"} - [Bro NIDS](https://www.bro.org/) export added in MISP in addition to Snort and Suricata. diff --git a/_posts/2016-10-21-MISP-Internet-Drafts-Published.md b/content/blog/2016-10-21-MISP-Internet-Drafts-Published.md similarity index 97% rename from _posts/2016-10-21-MISP-Internet-Drafts-Published.md rename to content/blog/2016-10-21-MISP-Internet-Drafts-Published.md index 4b65252..4456104 100755 --- a/_posts/2016-10-21-MISP-Internet-Drafts-Published.md +++ b/content/blog/2016-10-21-MISP-Internet-Drafts-Published.md @@ -1,7 +1,8 @@ --- title: MISP Internet Drafts Published +date: 2016-10-21 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- We recently released two Internet-Drafts describing the MISP format: diff --git a/_posts/2016-10-22-MISP-2.4.53-released.md b/content/blog/2016-10-22-MISP-2.4.53-released.md similarity index 95% rename from _posts/2016-10-22-MISP-2.4.53-released.md rename to content/blog/2016-10-22-MISP-2.4.53-released.md index ce92440..f8dc38f 100755 --- a/_posts/2016-10-22-MISP-2.4.53-released.md +++ b/content/blog/2016-10-22-MISP-2.4.53-released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.53 released +date: 2016-10-22 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version [2.4.53](https://github.com/MISP/MISP/tree/v2.4.53) of MISP including several security fixes has been released. diff --git a/_posts/2016-11-04-MISP-2.4.54-released.md b/content/blog/2016-11-04-MISP-2.4.54-released.md similarity index 97% rename from _posts/2016-11-04-MISP-2.4.54-released.md rename to content/blog/2016-11-04-MISP-2.4.54-released.md index 00713e1..17aa46b 100755 --- a/_posts/2016-11-04-MISP-2.4.54-released.md +++ b/content/blog/2016-11-04-MISP-2.4.54-released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.54 released +date: 2016-11-04 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version [2.4.54](https://github.com/MISP/MISP/tree/v2.4.54) of MISP including new features, bug and security fixes. diff --git a/_posts/2016-11-16-Independence-and-Threat-Intelligence-Platforms.md b/content/blog/2016-11-16-Independence-and-Threat-Intelligence-Platforms.md similarity index 97% rename from _posts/2016-11-16-Independence-and-Threat-Intelligence-Platforms.md rename to content/blog/2016-11-16-Independence-and-Threat-Intelligence-Platforms.md index 78d4968..264d7d7 100755 --- a/_posts/2016-11-16-Independence-and-Threat-Intelligence-Platforms.md +++ b/content/blog/2016-11-16-Independence-and-Threat-Intelligence-Platforms.md @@ -1,7 +1,8 @@ --- title: Independence and Threat Intelligence Platforms +date: 2016-11-16 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- After the recent news of a [Threat Intelligence Platform vendor stopping its activities](http://soltra.com/en/articles/soltra-wind-down/), we have received some questions about our strategies as a Threat Intelligence Platform. diff --git a/_posts/2016-11-22-MISP-2.4.55.released.md b/content/blog/2016-11-22-MISP-2.4.55.released.md similarity index 95% rename from _posts/2016-11-22-MISP-2.4.55.released.md rename to content/blog/2016-11-22-MISP-2.4.55.released.md index f930c77..9db00e3 100755 --- a/_posts/2016-11-22-MISP-2.4.55.released.md +++ b/content/blog/2016-11-22-MISP-2.4.55.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.55 released +date: 2016-11-22 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.55](https://github.com/MISP/MISP/tree/v2.4.55) has just been released, including bug fixes and improvements. diff --git a/_posts/2016-12-07-MISP.2.4.56.released.md b/content/blog/2016-12-07-MISP.2.4.56.released.md similarity index 86% rename from _posts/2016-12-07-MISP.2.4.56.released.md rename to content/blog/2016-12-07-MISP.2.4.56.released.md index 0829484..9c5a4e4 100755 --- a/_posts/2016-12-07-MISP.2.4.56.released.md +++ b/content/blog/2016-12-07-MISP.2.4.56.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.56 released +date: 2016-12-07 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.56](https://github.com/MISP/MISP/tree/v2.4.56) has been released, including bug fixes and improvements. @@ -10,8 +11,8 @@ This is the first version introducing the [misp-galaxy](https://github.com/MISP/ large objects called cluster that can be attached to MISP events or (in the near future) attributes. A cluster can be composed of one or more elements, which are expressed as key-value pairs. You can now directly benefit from the shared galaxy with threat actors and tools used by attackers in MISP. -![MISP galaxy](/assets/images/misp/blog/galaxy.png){:class="img-responsive"} -![MISP galaxy](/assets/images/misp/blog/cluster.png){:class="img-responsive"} +![MISP galaxy](/img/blog/galaxy.png){:class="img-responsive"} +![MISP galaxy](/img/blog/cluster.png){:class="img-responsive"} The release includes various improvements such as: diff --git a/_posts/2016-12-19-MISP.2.4.57.released.md b/content/blog/2016-12-19-MISP.2.4.57.released.md similarity index 97% rename from _posts/2016-12-19-MISP.2.4.57.released.md rename to content/blog/2016-12-19-MISP.2.4.57.released.md index c56ed1b..5b701ec 100755 --- a/_posts/2016-12-19-MISP.2.4.57.released.md +++ b/content/blog/2016-12-19-MISP.2.4.57.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.57 released +date: 2016-12-19 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.57](https://github.com/MISP/MISP/tree/v2.4.57) has been released, including bug fixes and improvements. diff --git a/_posts/2016-12-22-MISP.2.4.58.released.md b/content/blog/2016-12-22-MISP.2.4.58.released.md similarity index 92% rename from _posts/2016-12-22-MISP.2.4.58.released.md rename to content/blog/2016-12-22-MISP.2.4.58.released.md index f70dd21..e7c7e2a 100755 --- a/_posts/2016-12-22-MISP.2.4.58.released.md +++ b/content/blog/2016-12-22-MISP.2.4.58.released.md @@ -1,12 +1,13 @@ --- title: MISP 2.4.58 released +date: 2016-12-22 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.58](https://github.com/MISP/MISP/tree/v2.4.58) has been released, including bug fixes and a specific improvement to the correlation feature. -![MISP galaxy](/assets/images/misp/blog/correlation.png){:class="img-responsive"} +![MISP galaxy](/img/blog/correlation.png){:class="img-responsive"} Correlation can be disabled at the instance level, or, if a new setting is enabled, at the event or at the attribute level by a site admin or the creator of the event. The latter is an optional feature that can be enabled or disabled system-wide in MISP. This allows for a flexible scheme, supporting situations where the correlations of certain events or attributes are not interesting for the analysts. This feature is also available via the API. diff --git a/_posts/2017-01-16-Information-Sharing-Maturity-Model.md b/content/blog/2017-01-16-Information-Sharing-Maturity-Model.md similarity index 99% rename from _posts/2017-01-16-Information-Sharing-Maturity-Model.md rename to content/blog/2017-01-16-Information-Sharing-Maturity-Model.md index d093264..12c1394 100755 --- a/_posts/2017-01-16-Information-Sharing-Maturity-Model.md +++ b/content/blog/2017-01-16-Information-Sharing-Maturity-Model.md @@ -1,7 +1,8 @@ --- title: Information Sharing Maturity Model +date: 2017-01-16 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- Here at the *MISP project*, we are practical oriented people. We create software (from *MISP core* to *MISP workbench*), develop data models (such as [taxonomies](https://github.com/MISP/misp-taxonomies), [warning-lists](https://github.com/MISP/misp-warninglists) and [galaxies](https://github.com/MISP/misp-galaxy)) and build practical standards to solve information sharing challenges and improve the general state of information sharing. That's what we strive for. If we lack something, we build it. If we see a requirement, we fullfil it. diff --git a/_posts/2017-01-17-MISP.2.4.60.released.md b/content/blog/2017-01-17-MISP.2.4.60.released.md similarity index 92% rename from _posts/2017-01-17-MISP.2.4.60.released.md rename to content/blog/2017-01-17-MISP.2.4.60.released.md index a956bed..bd0cb8d 100755 --- a/_posts/2017-01-17-MISP.2.4.60.released.md +++ b/content/blog/2017-01-17-MISP.2.4.60.released.md @@ -1,12 +1,13 @@ --- title: MISP 2.4.60 released +date: 2017-01-17 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.60](https://github.com/MISP/MISP/tree/v2.4.60) has been released, including bug fixes and the long awaited attribute-level tagging feature. -![MISP attribute level tagging](/assets/images/misp/blog/attribute-level.png){:class="img-responsive"} +![MISP attribute level tagging](/img/blog/attribute-level.png){:class="img-responsive"} All tags (local or from taxonomies) can now be also applied at the attribute level. This allows analysts or users to easily classify attributes within an event. Many of the taxonomies have useful properties that can be applied to provide additional contextual information to attributes. diff --git a/_posts/2017-01-22-MISP.2.4.61.released.md b/content/blog/2017-01-22-MISP.2.4.61.released.md similarity index 91% rename from _posts/2017-01-22-MISP.2.4.61.released.md rename to content/blog/2017-01-22-MISP.2.4.61.released.md index 2099dbf..44589fe 100755 --- a/_posts/2017-01-22-MISP.2.4.61.released.md +++ b/content/blog/2017-01-22-MISP.2.4.61.released.md @@ -1,12 +1,13 @@ --- title: MISP 2.4.61 released +date: 2017-01-22 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.61](https://github.com/MISP/MISP/tree/v2.4.61) has been released, including a critical bug fix, new features and minor updates. We strongly recommend to update MISP to this latest version. -![MISP warning-list](/assets/images/misp/blog/warning-list.png){:class="img-responsive"} +![MISP warning-list](/img/blog/warning-list.png){:class="img-responsive"} [Warning lists](https://github.com/MISP/misp-warninglists) has been significantly updated with two new types: ```hostname``` and ```substring```. This allows to make more granular matching to find additional potential false-positives. The ```hostname``` type allows smart substring matching within URLs. diff --git a/_posts/2017-01-26-MISP.2.4.62.released.md b/content/blog/2017-01-26-MISP.2.4.62.released.md similarity index 97% rename from _posts/2017-01-26-MISP.2.4.62.released.md rename to content/blog/2017-01-26-MISP.2.4.62.released.md index e3bdff3..74b6c20 100755 --- a/_posts/2017-01-26-MISP.2.4.62.released.md +++ b/content/blog/2017-01-26-MISP.2.4.62.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.62 and PyMISP 2.4.62 released +date: 2017-01-26 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.62](https://github.com/MISP/MISP/tree/v2.4.62) has been released, including bug fixes and new features. diff --git a/_posts/2017-02-01-MISP.2.4.63.released.md b/content/blog/2017-02-01-MISP.2.4.63.released.md similarity index 96% rename from _posts/2017-02-01-MISP.2.4.63.released.md rename to content/blog/2017-02-01-MISP.2.4.63.released.md index 50bc5c4..e5809d6 100755 --- a/_posts/2017-02-01-MISP.2.4.63.released.md +++ b/content/blog/2017-02-01-MISP.2.4.63.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.63 released +date: 2017-02-01 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.63](https://github.com/MISP/MISP/tree/v2.4.63) has been released, including bug fixes and new features. diff --git a/_posts/2017-02-09-MISP.2.4.65.released.md b/content/blog/2017-02-09-MISP.2.4.65.released.md similarity index 96% rename from _posts/2017-02-09-MISP.2.4.65.released.md rename to content/blog/2017-02-09-MISP.2.4.65.released.md index 647a7fe..4d0a3ee 100755 --- a/_posts/2017-02-09-MISP.2.4.65.released.md +++ b/content/blog/2017-02-09-MISP.2.4.65.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.65 released +date: 2017-02-09 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.65](https://github.com/MISP/MISP/tree/v2.4.65) (and 2.4.64) has been released, including bug fixes and new features. diff --git a/_posts/2017-02-16-Sighting-The-Next-Level.md b/content/blog/2017-02-16-Sighting-The-Next-Level.md similarity index 96% rename from _posts/2017-02-16-Sighting-The-Next-Level.md rename to content/blog/2017-02-16-Sighting-The-Next-Level.md index a49e288..84f3556 100755 --- a/_posts/2017-02-16-Sighting-The-Next-Level.md +++ b/content/blog/2017-02-16-Sighting-The-Next-Level.md @@ -1,7 +1,8 @@ --- title: Sighting the next level +date: 2017-02-16 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- Sighting is an [endless topic of discussion](https://lists.oasis-open.org/archives/cti-stix/201508/msg00019.html). This is a required feature especially when information or indicators are regularly shared to gather feedback from users said shared data. Adequate sightings can be an incredible source of information in order to describe the life-time of an indicator, its evolution and especially to ensure the understanding of indicators among a group of users using the information to detect, mitigate or block malicious activities in their infrastructures. The potential is endless, potentially being a significant gain for organised communities of infosec professionals sharing information or even serve as a requirement for advanced algorithms ranging from machine learning to reinforcement learning. But to reach such a state of a feedback loop, you first require a functional model of sighting. @@ -26,7 +27,7 @@ MISP 2.4.66 has been released including the improved sightings feature. As you c
diff --git a/_posts/2017-02-24-MISP.2.4.67.released.md b/content/blog/2017-02-24-MISP.2.4.67.released.md similarity index 91% rename from _posts/2017-02-24-MISP.2.4.67.released.md rename to content/blog/2017-02-24-MISP.2.4.67.released.md index 9b46b97..d32d84c 100755 --- a/_posts/2017-02-24-MISP.2.4.67.released.md +++ b/content/blog/2017-02-24-MISP.2.4.67.released.md @@ -1,14 +1,15 @@ --- title: MISP 2.4.67 released +date: 2017-02-24 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.67](https://github.com/MISP/MISP/tree/v2.4.67) has been released, including improvements to the sighting feature, user management and activity visualisation. Sighting activities over tags and galaxy clusters are now visualised using sparklines, giving us an interesting outlook of contextual activity: -![MISP attribute level tagging](/assets/images/misp/blog/tag-activity.png){:class="img-responsive"} +![MISP attribute level tagging](/img/blog/tag-activity.png){:class="img-responsive"} Advanced sighting activity is now available at the event level to view the summary of sightings submitted at the attribute level. diff --git a/_posts/2017-03-08-MISP.2.4.68.released.md b/content/blog/2017-03-08-MISP.2.4.68.released.md similarity index 96% rename from _posts/2017-03-08-MISP.2.4.68.released.md rename to content/blog/2017-03-08-MISP.2.4.68.released.md index 08acbad..f550135 100755 --- a/_posts/2017-03-08-MISP.2.4.68.released.md +++ b/content/blog/2017-03-08-MISP.2.4.68.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.68 released +date: 2017-03-08 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.68](https://github.com/MISP/MISP/tree/v2.4.68) has been released including multiple bug fixes and improvements. diff --git a/_posts/2017-03-10-MISP.2.4.69.released.md b/content/blog/2017-03-10-MISP.2.4.69.released.md similarity index 93% rename from _posts/2017-03-10-MISP.2.4.69.released.md rename to content/blog/2017-03-10-MISP.2.4.69.released.md index 60f69ca..b68263a 100755 --- a/_posts/2017-03-10-MISP.2.4.69.released.md +++ b/content/blog/2017-03-10-MISP.2.4.69.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.69 released +date: 2017-03-10 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.69](https://github.com/MISP/MISP/tree/v2.4.69) has been released including multiple security bug fixes and minor improvements. diff --git a/_posts/2017-03-26-MISP.2.4.70.released.md b/content/blog/2017-03-26-MISP.2.4.70.released.md similarity index 96% rename from _posts/2017-03-26-MISP.2.4.70.released.md rename to content/blog/2017-03-26-MISP.2.4.70.released.md index 295bfa9..d048779 100755 --- a/_posts/2017-03-26-MISP.2.4.70.released.md +++ b/content/blog/2017-03-26-MISP.2.4.70.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.70 released +date: 2017-03-26 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.70](https://github.com/MISP/MISP/tree/v2.4.70) has been released including new features, improvements and important bug fixes. diff --git a/_posts/2017-04-11-MISP.2.4.71.released.md b/content/blog/2017-04-11-MISP.2.4.71.released.md similarity index 97% rename from _posts/2017-04-11-MISP.2.4.71.released.md rename to content/blog/2017-04-11-MISP.2.4.71.released.md index 98e8ef7..7c4964e 100755 --- a/_posts/2017-04-11-MISP.2.4.71.released.md +++ b/content/blog/2017-04-11-MISP.2.4.71.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.71 released +date: 2017-04-11 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.71](https://github.com/MISP/MISP/tree/v2.4.71) has been released including new features, improvements and important bug fixes. diff --git a/_posts/2017-04-14-MISP.2.4.72.released.md b/content/blog/2017-04-14-MISP.2.4.72.released.md similarity index 98% rename from _posts/2017-04-14-MISP.2.4.72.released.md rename to content/blog/2017-04-14-MISP.2.4.72.released.md index 26f3acb..7b8c181 100755 --- a/_posts/2017-04-14-MISP.2.4.72.released.md +++ b/content/blog/2017-04-14-MISP.2.4.72.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.72 released +date: 2017-04-14 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.72](https://github.com/MISP/MISP/tree/v2.4.72) has been released including improvements and important bug fixes. diff --git a/_posts/2017-05-09-MISP.2.4.73.released.md b/content/blog/2017-05-09-MISP.2.4.73.released.md similarity index 95% rename from _posts/2017-05-09-MISP.2.4.73.released.md rename to content/blog/2017-05-09-MISP.2.4.73.released.md index ed816ab..c91d556 100755 --- a/_posts/2017-05-09-MISP.2.4.73.released.md +++ b/content/blog/2017-05-09-MISP.2.4.73.released.md @@ -1,14 +1,15 @@ --- title: MISP 2.4.73 released +date: 2017-05-09 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.73](https://github.com/MISP/MISP/tree/v2.4.73) has been released including new features, improvements and bug fixes. A new module type Cortex has been introduced allowing for easy integration of MISP and Cortex. [Cortex](https://github.com/CERT-BDF/Cortex) is the analysis engine part of the [TheHive Project](https://thehive-project.org/) which supports expansion services from Cortex within MISP. A new setting has been added to support Cortex similarly to MISP expansion modules where you set the remote Cortex instance. MISP includes a new Cortex attribute type to allow for the raw analysis to be stored along with the event for subsequent analysis. -![feed overlap analysis matrix](/assets/images/misp/blog/feed-overlap-analys-matrix.png){:class="img-responsive"} +![feed overlap analysis matrix](/img/blog/feed-overlap-analys-matrix.png){:class="img-responsive"} The MISP feed handling was reworked to expand the functionality and avoid the past limitation: diff --git a/_posts/2017-05-30-MISP.2.4.74.released.md b/content/blog/2017-05-30-MISP.2.4.74.released.md similarity index 97% rename from _posts/2017-05-30-MISP.2.4.74.released.md rename to content/blog/2017-05-30-MISP.2.4.74.released.md index 9c1060f..1a0ebd1 100755 --- a/_posts/2017-05-30-MISP.2.4.74.released.md +++ b/content/blog/2017-05-30-MISP.2.4.74.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.74 released +date: 2017-05-30 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.74](https://github.com/MISP/MISP/tree/v2.4.74) has been released including new features, improvements and bug fixes. diff --git a/_posts/2017-06-13-MISP.2.4.75.released.md b/content/blog/2017-06-13-MISP.2.4.75.released.md similarity index 97% rename from _posts/2017-06-13-MISP.2.4.75.released.md rename to content/blog/2017-06-13-MISP.2.4.75.released.md index c2d9305..3907d77 100755 --- a/_posts/2017-06-13-MISP.2.4.75.released.md +++ b/content/blog/2017-06-13-MISP.2.4.75.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.75 released +date: 2017-06-13 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.75](https://github.com/MISP/MISP/tree/v2.4.75) has been released including bug fixes and a set of performance improvements. diff --git a/_posts/2017-06-21-MISP.2.4.76.released.md b/content/blog/2017-06-21-MISP.2.4.76.released.md similarity index 97% rename from _posts/2017-06-21-MISP.2.4.76.released.md rename to content/blog/2017-06-21-MISP.2.4.76.released.md index e6007e8..a800370 100755 --- a/_posts/2017-06-21-MISP.2.4.76.released.md +++ b/content/blog/2017-06-21-MISP.2.4.76.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.76 released +date: 2017-06-21 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.76](https://github.com/MISP/MISP/tree/v2.4.76) has been released including bug fixes and a set of performance improvements at the ingestion level. diff --git a/_posts/2017-07-12-MISP.2.4.77.released.md b/content/blog/2017-07-12-MISP.2.4.77.released.md similarity index 97% rename from _posts/2017-07-12-MISP.2.4.77.released.md rename to content/blog/2017-07-12-MISP.2.4.77.released.md index 7dbf0d6..4853a4c 100755 --- a/_posts/2017-07-12-MISP.2.4.77.released.md +++ b/content/blog/2017-07-12-MISP.2.4.77.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.77 released +date: 2017-07-12 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.77](https://github.com/MISP/MISP/tree/v2.4.77) has been released including security fixes, bug fixes and various improvements. diff --git a/_posts/2017-08-06-MISP.2.4.78.released.md b/content/blog/2017-08-06-MISP.2.4.78.released.md similarity index 97% rename from _posts/2017-08-06-MISP.2.4.78.released.md rename to content/blog/2017-08-06-MISP.2.4.78.released.md index 63e7387..8d425c6 100755 --- a/_posts/2017-08-06-MISP.2.4.78.released.md +++ b/content/blog/2017-08-06-MISP.2.4.78.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.78 released +date: 2017-08-06 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.78](https://github.com/MISP/MISP/tree/v2.4.77) has been released including an important security fix (if you use sharing groups), multiple bug fixes and some new functionalities. diff --git a/_posts/2017-08-25-MISP.2.4.79.released.md b/content/blog/2017-08-25-MISP.2.4.79.released.md similarity index 97% rename from _posts/2017-08-25-MISP.2.4.79.released.md rename to content/blog/2017-08-25-MISP.2.4.79.released.md index 1bbffcf..46f35f6 100755 --- a/_posts/2017-08-25-MISP.2.4.79.released.md +++ b/content/blog/2017-08-25-MISP.2.4.79.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.79 released +date: 2017-08-25 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.79](https://github.com/MISP/MISP/tree/v2.4.79) has been released including an important security fix (persistent XSS on comment field), multiple bug fixes and new functionalities. diff --git a/_posts/2017-09-18-MISP.2.4.80.released.md b/content/blog/2017-09-18-MISP.2.4.80.released.md similarity index 96% rename from _posts/2017-09-18-MISP.2.4.80.released.md rename to content/blog/2017-09-18-MISP.2.4.80.released.md index 2cbd5d5..98106ec 100755 --- a/_posts/2017-09-18-MISP.2.4.80.released.md +++ b/content/blog/2017-09-18-MISP.2.4.80.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.80 released (aka MISP objects release) +date: 2017-09-18 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.80](https://github.com/MISP/MISP/tree/v2.4.80) has been released including the most awaited [MISP objects](https://github.com/MISP/misp-objects) feature along with other new features, security fix [CVE-2017-14337](https://www.circl.lu/advisory/CVE-2017-14337/) and improvements. @@ -19,7 +20,7 @@ The default MISP object templates included are: ail-leak, cookie, credit-card, d An example which describes a DGA (Domain Generation Algorithm) linked to two domain indicators using the MISP object functionality: -![DGA expressed as MISP object](/assets/images/misp/blog/DGA-in-MISP.png){:class="img-responsive"} +![DGA expressed as MISP object](/img/blog/DGA-in-MISP.png){:class="img-responsive"} Relationships can be described from an existing list of relationship types (e.g. `executed-by`, `impersonates`, `communicates-with`,...) or by values from your own relationship vocabulary. This allows to model a fairly large set of cases from incident, collected intelligence, attacks or course-of-action to malware analysis. diff --git a/_posts/2017-09-18-MISP.2.4.81.released.md b/content/blog/2017-09-18-MISP.2.4.81.released.md similarity index 95% rename from _posts/2017-09-18-MISP.2.4.81.released.md rename to content/blog/2017-09-18-MISP.2.4.81.released.md index 432559a..ede10d4 100755 --- a/_posts/2017-09-18-MISP.2.4.81.released.md +++ b/content/blog/2017-09-18-MISP.2.4.81.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.81 released (aka new graphical visualisation and STIX 2.0 export) +date: 2017-09-18 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.81](https://github.com/MISP/MISP/tree/v2.4.81) has been released including a significant rework of the graphical visualisation, support for STIX 2.0 export, multiple bug-fixes and improvements for misp-objects. @@ -11,7 +12,7 @@ The new correlation graph has been improved and now includes the correlation at The navigation and expansion within the correlation graph has now a series of shortcut keys (`q` and `e`) to quickly navigate within large graphs. There is also a new contextual information pane, to quickly show the currently selected and hovered nodes. This improves the navigation over large graphs and quickly expands the information from the selected nodes. -![MISP 2.4.81 new correlation graph](/assets/images/misp/blog/correlation-graph.png){:class="img-responsive"} +![MISP 2.4.81 new correlation graph](/img/blog/correlation-graph.png){:class="img-responsive"} STIX 2.0 is now supported as an export format in this release. Even though the STIX 2.0 format is still unpublished and at an early stage, we decided to implement a first export tool to see the gaps of the format and helps our users to test the export with potential tools which start to support the version 2.0. As MISP commitment is to support the maximum of format, STIX 1.1 has been also expanded diff --git a/_posts/2017-11-10-MISP.2.4.82.released.md b/content/blog/2017-11-10-MISP.2.4.82.released.md similarity index 96% rename from _posts/2017-11-10-MISP.2.4.82.released.md rename to content/blog/2017-11-10-MISP.2.4.82.released.md index f0b5985..4d36216 100755 --- a/_posts/2017-11-10-MISP.2.4.82.released.md +++ b/content/blog/2017-11-10-MISP.2.4.82.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.82 released (aka improved pub-sub ZMQ) +date: 2017-11-10 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.82](https://github.com/MISP/MISP/tree/v2.4.82) has been released including an improved publish-subscribe ZMQ format, improvements in the feeds system, sightings are now ingested and synchronised among MISP instances, many bug fixes and export improvements. @@ -11,7 +12,7 @@ to deliver additional information to the subscribers. The system can be used to
diff --git a/_posts/2017-12-06-MISP.2.4.83.released.md b/content/blog/2017-12-06-MISP.2.4.83.released.md similarity index 98% rename from _posts/2017-12-06-MISP.2.4.83.released.md rename to content/blog/2017-12-06-MISP.2.4.83.released.md index 85c27a0..ef717de 100755 --- a/_posts/2017-12-06-MISP.2.4.83.released.md +++ b/content/blog/2017-12-06-MISP.2.4.83.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.83 released (aka attributes-level tag filtering and more) +date: 2017-12-06 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.83](https://github.com/MISP/MISP/tree/v2.4.83) has been released including attribute level tag filtering on synchronisation, full audit logging via ZMQ or Syslog, user email domain restriction at the org level, many more improvements and bug fixes. diff --git a/_posts/2017-12-22-MISP.2.4.85.released.md b/content/blog/2017-12-22-MISP.2.4.85.released.md similarity index 96% rename from _posts/2017-12-22-MISP.2.4.85.released.md rename to content/blog/2017-12-22-MISP.2.4.85.released.md index ce065de..b0f6e58 100755 --- a/_posts/2017-12-22-MISP.2.4.85.released.md +++ b/content/blog/2017-12-22-MISP.2.4.85.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.85 released (aka feeds and warning-lists improvement and more) +date: 2017-12-22 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.85](https://github.com/MISP/MISP/tree/v2.4.85) has been released including improvements to the feed ingestion performance, warning-list handling and many bug fixes. @@ -25,7 +26,7 @@ Improvement and cleanup in the event index: Various UI improvements to clean up the interface for the analysts, including changes such as the collapse of attributes with highly correlating events: -![collapse of correlation](/assets/images/misp/blog/collapse.png){:class="img-responsive"} +![collapse of correlation](/img/blog/collapse.png){:class="img-responsive"} The advanced sighting view on objects is now properly working. diff --git a/_posts/2018-01-09-Using-MISP-to-share-vulnerability-information-efficiently.md b/content/blog/2018-01-09-Using-MISP-to-share-vulnerability-information-efficiently.md similarity index 93% rename from _posts/2018-01-09-Using-MISP-to-share-vulnerability-information-efficiently.md rename to content/blog/2018-01-09-Using-MISP-to-share-vulnerability-information-efficiently.md index 9e4d4b4..1c1eadc 100755 --- a/_posts/2018-01-09-Using-MISP-to-share-vulnerability-information-efficiently.md +++ b/content/blog/2018-01-09-Using-MISP-to-share-vulnerability-information-efficiently.md @@ -1,7 +1,8 @@ --- title: Using MISP to share vulnerability information efficiently +date: 2018-01-09 layout: post -featured: /assets/images/misp/blog/vul02.png +banner: /img/blog/vul02.png --- # Using MISP to share vulnerability information efficiently @@ -26,18 +27,18 @@ Sharing a set of vulnerabilities to a trusted group is straightforward. First yo vulnerabilities and assign the corresponding sharing group. An event is just a container with meta-data associated with it such as a classification or a generic description. -![](/assets/images/misp/blog/vul01.png) +![](/img/blog/vul01.png) Then when your event is created, the event can be used to attach attributes or objects. If you want to share vulnerability information, a vulnerability object can be added to describe the vulnerability. -![](/assets/images/misp/blog/vul02.png) +![](/img/blog/vul02.png) The vulnerability object is composed of various attributes such as the vulnerable configuration expressed as a CPE value and can be added multiple times if you have different vulnerable configurations. -![](/assets/images/misp/blog/vul03.png) +![](/img/blog/vul03.png) -![](/assets/images/misp/blog/vul04.png) +![](/img/blog/vul04.png) Another effective aspect when pre-sharing vulnerability within MISP is to benefit from the Globally Unique Identifier allocation (GUID) for each attributes. This allows to share efficiently without the need to allocate unique identifier. If a CVE allocation is done after, this has no impact on the event when the vulnerability identifiers are set. diff --git a/_posts/2018-01-16-MISP.2.4.86.released.md b/content/blog/2018-01-16-MISP.2.4.86.released.md similarity index 98% rename from _posts/2018-01-16-MISP.2.4.86.released.md rename to content/blog/2018-01-16-MISP.2.4.86.released.md index 9ea8342..f43786a 100755 --- a/_posts/2018-01-16-MISP.2.4.86.released.md +++ b/content/blog/2018-01-16-MISP.2.4.86.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.86 released (aka sharing groups improvement, large information sharing communities support and more) +date: 2018-01-16 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.86](https://github.com/MISP/MISP/tree/v2.4.86) has been released including improvements to the sharing groups and their respective APIs, granular access control of MISP-modules at an instance-level along with the usual set of bug fixes. diff --git a/_posts/2018-01-28-MISP.2.4.87.md b/content/blog/2018-01-28-MISP.2.4.87.md similarity index 98% rename from _posts/2018-01-28-MISP.2.4.87.md rename to content/blog/2018-01-28-MISP.2.4.87.md index a6db7e5..afda86b 100755 --- a/_posts/2018-01-28-MISP.2.4.87.md +++ b/content/blog/2018-01-28-MISP.2.4.87.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.87 released (aka translate everything, improvements everywhere and more) +date: 2018-01-28 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.87](https://github.com/MISP/MISP/tree/v2.4.87) has been released including a massive contribution enabling support for internationalisation and localisation in the MISP UI (a huge thank to Steve Clement of CIRCL for the tedious work), as well as a host of improvements to the UI, feed and APIs, including bug fixes and speed improvements. diff --git a/_posts/2018-02-21-MISP.2.4.88.released.md b/content/blog/2018-02-21-MISP.2.4.88.released.md similarity index 98% rename from _posts/2018-02-21-MISP.2.4.88.released.md rename to content/blog/2018-02-21-MISP.2.4.88.released.md index 0f38d49..cb4ff79 100755 --- a/_posts/2018-02-21-MISP.2.4.88.released.md +++ b/content/blog/2018-02-21-MISP.2.4.88.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.88 released (aka Fuzzy hashing correlation, STIX 1.1 import and many API improvements) +date: 2018-02-21 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.88](https://github.com/MISP/MISP/tree/v2.4.88) has been released including fuzzy hashing correlation (ssdeep), STIX 1.1 import functionality, various API improvements and many bug fixes diff --git a/_posts/2018-03-23-MISP.2.4.89.released.md b/content/blog/2018-03-23-MISP.2.4.89.released.md similarity index 94% rename from _posts/2018-03-23-MISP.2.4.89.released.md rename to content/blog/2018-03-23-MISP.2.4.89.released.md index cb1c1fc..8bbbb91 100755 --- a/_posts/2018-03-23-MISP.2.4.89.released.md +++ b/content/blog/2018-03-23-MISP.2.4.89.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.89 released (aka Event graph viewer/editor) +date: 2018-03-23 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.89](https://github.com/MISP/MISP/tree/v2.4.89) has been released including a new MISP event graph viewer/editor, many API improvements and critical bug fixes (including security related bug fixes). @@ -10,7 +11,7 @@ We introduced a new functionality allowing analysts and MISP users to view objec
diff --git a/_posts/2018-04-19-Extended-Events-Feature.md b/content/blog/2018-04-19-Extended-Events-Feature.md similarity index 96% rename from _posts/2018-04-19-Extended-Events-Feature.md rename to content/blog/2018-04-19-Extended-Events-Feature.md index 5c1db23..b4735c6 100755 --- a/_posts/2018-04-19-Extended-Events-Feature.md +++ b/content/blog/2018-04-19-Extended-Events-Feature.md @@ -1,7 +1,8 @@ --- title: Introducing The New Extended Events Feature in MISP +date: 2018-04-19 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- # Introducing Extended Events @@ -27,13 +28,13 @@ To create an extension event, simply enter the UUID or ID of the event in the "E Users viewing the original report, will now see a new field called "Extended by" as shown below: -![A MISP event extended by another event](/assets/images/misp/blog/extended.png){:class="img-responsive"} +![A MISP event extended by another event](/img/blog/extended.png){:class="img-responsive"} Clicking on the atomic view / extended view toggle button will allow you to jump from the classical event view to the extended event view. The extended view will add all of the relations, tags, galaxy clusters, attributes and objects of the extender events. The attribute list in extended view also shows the event it originates from along with the creator organisation. Keep in mind that duplicates across several events are not culled. Extending an event is easy and a nifty lookup interface helps you to select the appropriate event to extend: -![Extending a event when creating a new MISP event](/assets/images/misp/blog/extendadd.png){:class="img-responsive"} +![Extending a event when creating a new MISP event](/img/blog/extendadd.png){:class="img-responsive"} In the above case, OSINT information contained within an event is extended with additional threat hunting information which are limited to your organisation. The major advantage of such an approach is allowing any organisation to expand information without touching the original event. diff --git a/_posts/2018-04-20-MISP.2.4.90.released.md b/content/blog/2018-04-20-MISP.2.4.90.released.md similarity index 98% rename from _posts/2018-04-20-MISP.2.4.90.released.md rename to content/blog/2018-04-20-MISP.2.4.90.released.md index 25d1be0..af25551 100755 --- a/_posts/2018-04-20-MISP.2.4.90.released.md +++ b/content/blog/2018-04-20-MISP.2.4.90.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.90 released (aka Extended Events release) +date: 2018-04-20 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.90](https://github.com/MISP/MISP/tree/v2.4.90) has been released including the new extended events feature along with many updates in improvements in the API, user-interface (including many improvement in the graph editor) and many bug fixes. diff --git a/_posts/2018-05-16-MISP.2.4.91.released.md b/content/blog/2018-05-16-MISP.2.4.91.released.md similarity index 92% rename from _posts/2018-05-16-MISP.2.4.91.released.md rename to content/blog/2018-05-16-MISP.2.4.91.released.md index a028edd..148646d 100755 --- a/_posts/2018-05-16-MISP.2.4.91.released.md +++ b/content/blog/2018-05-16-MISP.2.4.91.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.91 released (aka distribution visualisation, galaxy at attribute level and privacy notice list) +date: 2018-05-16 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.91](https://github.com/MISP/MISP/tree/v2.4.91) has been released including new major features, improvements and bug fixes. @@ -13,14 +14,14 @@ become quite larger, with long lists of objects and attributes, analysts need to allows them to view the items per distribution level including the associated sharing groups. The visualisation is dynamic and can be used to filter the given attributes matching a specific distribution setting within the event. -![Visualisation of a MISP event and how the sharing of attributes will take place](/assets/images/misp/blog/sharing.png){:class="img-responsive"} +![Visualisation of a MISP event and how the sharing of attributes will take place](/img/blog/sharing.png){:class="img-responsive"} ### Galaxy at attribute level [MISP Galaxy](/galaxy.html) includes a large number of libraries to assist in classifying events based on threat actors, kill chains or actor techniques such as described in the [MITRE ATT&CK](https://attack.mitre.org/wiki/Main_Page) galaxy. Initially, MISP galaxies were limited to be attached to MISP events alone. As many users developed new galaxy cluster to map their own model, MISP 2.4.91 is now capable of attaching MISP clusters at the attribute level. In the example below, a vulnerability attribute can be then easily linked to the respective MITRE ATT&CK adversary technique supporting analysts trying to search for and pivot on techniques, but also supporting various more advanced automation scenarios. -![An example of a MISP galaxy such as MITRE ATT&CK attached to a specific attribute in MISP](/assets/images/misp/blog/exploitation.png){:class="img-responsive"} +![An example of a MISP galaxy such as MITRE ATT&CK attached to a specific attribute in MISP](/img/blog/exploitation.png){:class="img-responsive"} ### Privacy notice list and GDPR @@ -30,11 +31,11 @@ In MISP 2.4.91, we introduced the [MISP notice system](https://github.com/MISP/m We expect to see organisations using MISP to enable, disable or extend the notice lists to fit their specific policies, legal frameworks or local regulation frameworks. -![GDPR notice about a specific category](/assets/images/misp/blog/not1.png){:class="img-responsive"} +![GDPR notice about a specific category](/img/blog/not1.png){:class="img-responsive"} and notice lists are easily configurable: -![Notice lists are configurable](/assets/images/misp/blog/not2.png){:class="img-responsive"} +![Notice lists are configurable](/img/blog/not2.png){:class="img-responsive"} ### API diff --git a/_posts/2018-06-07-MISP.2.4.92.released.md b/content/blog/2018-06-07-MISP.2.4.92.released.md similarity index 98% rename from _posts/2018-06-07-MISP.2.4.92.released.md rename to content/blog/2018-06-07-MISP.2.4.92.released.md index 35df1f8..d8321ab 100755 --- a/_posts/2018-06-07-MISP.2.4.92.released.md +++ b/content/blog/2018-06-07-MISP.2.4.92.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.92 released (aka performance improvement) +date: 2018-06-07 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.92](https://github.com/MISP/MISP/tree/v2.4.92) has been released including aggressive performance boosts, various improvements and bug fixes. diff --git a/_posts/2018-06-27-MISP.2.4.93.released.md b/content/blog/2018-06-27-MISP.2.4.93.released.md similarity index 95% rename from _posts/2018-06-27-MISP.2.4.93.released.md rename to content/blog/2018-06-27-MISP.2.4.93.released.md index 6c281ed..6c48561 100755 --- a/_posts/2018-06-27-MISP.2.4.93.released.md +++ b/content/blog/2018-06-27-MISP.2.4.93.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.93 released (aka ATT&CK integration) +date: 2018-06-27 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.93](https://github.com/MISP/MISP/tree/v2.4.93) has been released including a much improved and tightly integrated [MITRE ATT&CK](https://attack.mitre.org) interface, a new event locking functionality, initial support for a multilingual interface, various fixes including a security fix ([CVE-2018-12649](https://cve.circl.lu/cve/CVE-2018-12649)). @@ -10,7 +11,7 @@ MITRE ATT&CK offers an excellent, efficient and very complete framework to descr
diff --git a/_posts/2018-08-06-MISP.2.4.94.released.md b/content/blog/2018-08-06-MISP.2.4.94.released.md similarity index 94% rename from _posts/2018-08-06-MISP.2.4.94.released.md rename to content/blog/2018-08-06-MISP.2.4.94.released.md index d4b6c2b..e953147 100755 --- a/_posts/2018-08-06-MISP.2.4.94.released.md +++ b/content/blog/2018-08-06-MISP.2.4.94.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.94 released (aka summer improvements) +date: 2018-08-06 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP [2.4.94](https://github.com/MISP/MISP/tree/v2.4.94) has been released including an improved event graph interface, a new Elasticsearch plugin, various extensions and enhancements to the API, clean-ups and many improvements. Even though it's summertime, we continuously work on the MISP project and a lot of changes were introduced. @@ -11,13 +12,13 @@ Major improvements have been implemented in the MISP event graph such as: - Export functionality added in the MISP event graph to export in PNG, JPEG, JSON format and Graphviz dot format. - Saving functionality to save the state of an event graph. This allows a user of an organisation to keep the state of the event graph and retrieve the history. -![New functionality in the MISP event graph to export the graph and save the state of the graph](/assets/images/misp/blog/save-graph.png){:class="img-responsive"} +![New functionality in the MISP event graph to export the graph and save the state of the graph](/img/blog/save-graph.png){:class="img-responsive"} The MITRE ATT&CK matrix user-interface has been extended to add directly techniques at event level without passing by the galaxy interface. A new functionality contributed allows users to log all MISP activities in Elasticsearch. It's pretty simple to configure thanks to its settings being part of the standard plugin settings system, so head over there to find the Elasticsearch configuration options. -![Configuring Elasticsearch with MISP](/assets/images/misp/blog/elasticsearch.png) +![Configuring Elasticsearch with MISP](/img/blog/elasticsearch.png) The CLI interface has been improved with the ability to get the API key of a given user, to force update the taxonomies, warning lists, notice lists and object templates. All of this serves to improve the automation of deployment of MISP instances without the need to use the UI. diff --git a/_posts/2018-09-06-MISP.2.4.95.released.md b/content/blog/2018-09-06-MISP.2.4.95.released.md similarity index 96% rename from _posts/2018-09-06-MISP.2.4.95.released.md rename to content/blog/2018-09-06-MISP.2.4.95.released.md index e9a2ec9..d66ef39 100755 --- a/_posts/2018-09-06-MISP.2.4.95.released.md +++ b/content/blog/2018-09-06-MISP.2.4.95.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.95 released (aka API search improvement) +date: 2018-09-06 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP ([2.4.95](https://github.com/MISP/MISP/tree/v2.4.95)) has been released with the first stage of a complete rework and refactoring of the API exports, allowing for more flexibility, improved search capabilities, performance and extendability. @@ -38,7 +39,7 @@ A debug functionality has been added in any API query to quickly show the SQL qu Many new [MISP modules](https://www.github.com/MISP/misp-modules) were included and we extend MISP to better support enrichment modules with large output (such as the Sigma to search queries converter). In this version, a new on-demand pop-up has been introduced to have a sticky hover to ease cut-and-paste or selection. -![A sigma export to SIEM rules via the misp-modules export](/assets/images/misp/blog/sigma.png){:class="img-responsive"} +![A sigma export to SIEM rules via the misp-modules export](/img/blog/sigma.png){:class="img-responsive"} A bro NIDS type has been added in MISP to support the exchange of raw bro NIDS signature within MISP communities. diff --git a/_posts/2018-10-09-MISP.2.4.96.released.md b/content/blog/2018-10-09-MISP.2.4.96.released.md similarity index 98% rename from _posts/2018-10-09-MISP.2.4.96.released.md rename to content/blog/2018-10-09-MISP.2.4.96.released.md index 94010c6..06a9371 100755 --- a/_posts/2018-10-09-MISP.2.4.96.released.md +++ b/content/blog/2018-10-09-MISP.2.4.96.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.96 released (aka API everywhere release) +date: 2018-10-09 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP ([2.4.96](https://github.com/MISP/MISP/tree/v2.4.96)) has been released with a complete rework, refactoring and simplification of the restSearch API, allowing for more flexibility, improved search capabilities, performance and extendability. diff --git a/_posts/2018-10-30-MISP.2.4.97.released.md b/content/blog/2018-10-30-MISP.2.4.97.released.md similarity index 93% rename from _posts/2018-10-30-MISP.2.4.97.released.md rename to content/blog/2018-10-30-MISP.2.4.97.released.md index 1494bac..77e5269 100755 --- a/_posts/2018-10-30-MISP.2.4.97.released.md +++ b/content/blog/2018-10-30-MISP.2.4.97.released.md @@ -1,16 +1,17 @@ --- title: MISP 2.4.97 released (aka so many new features) +date: 2018-10-30 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP ([2.4.97](https://github.com/MISP/MISP/tree/v2.4.97)) has been released with new features such as related tags, the sighting restSearch API, a new French localisation along with many improvements to the API and he import/export capabilities, such as improved support for [DHS AIS](https://www.us-cert.gov/ais) STIX 1 files. -![MISP event graph to display an overview of the relationships for a malware infection](https://www.misp-project.org/assets/images/misp/blog/eventgraph.png) +![MISP event graph to display an overview of the relationships for a malware infection](https://www.misp-project.org/img/blog/eventgraph.png) The new related tags functionality has been introduced to allow users to view the most commonly used tags for a specific attribute across all events. This can help analysts when deciding to use a specific classification based on previous analyses to reduce the time it takes to contextualise the new information. -![MISP event graph to display an overview of the relationships for a malware infection](https://www.misp-project.org/assets/images/misp/blog/related-tags.png) +![MISP event graph to display an overview of the relationships for a malware infection](https://www.misp-project.org/img/blog/related-tags.png) A new API has been introduced, allowing users to search [MISP sightings](https://www.misp.software/2017/02/16/Sighting-The-Next-Level.html) using a set of filter parameters along with a list of data formats (JSON, CSV or XML). The search is available on an event, attribute or instance level. You can easily search by time ranges (from, to or last) using the standard restSearch API syntax. diff --git a/_posts/2018-11-26-MISP.2.4.98.released.md b/content/blog/2018-11-26-MISP.2.4.98.released.md similarity index 96% rename from _posts/2018-11-26-MISP.2.4.98.released.md rename to content/blog/2018-11-26-MISP.2.4.98.released.md index d5a8a00..3d4ba2d 100755 --- a/_posts/2018-11-26-MISP.2.4.98.released.md +++ b/content/blog/2018-11-26-MISP.2.4.98.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.98 released (aka usability improvements and SleuthKit mactime import) +date: 2018-11-26 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP ([2.4.98](https://github.com/MISP/MISP/tree/v2.4.98)) has been released with new features such as improved UI consistency (such as attributes search output), improved validation error messages, a new built-in experimental SleuthKit mactime import, new small features and many bugs fixed. @@ -13,8 +14,8 @@ The output of the search interface is now consistent with standard attributes vi A new experimental import functionality has been included to import SleuthKit mactime timelines from MISP directly. The user can import one or more mactime timelines in MISP, which will be included as a mactime object to describe forensic activities on an analysed file system. The import is a two-step process where the user can cherry pick the forensic events which took place and select the meaningful activity to be added in a MISP event. -![SleuthKit mactime import in MISP](https://www.misp-project.org/assets/images/misp/blog/mactime1.png) -![SleuthKit mactime imported in MISP as objects](https://www.misp-project.org/assets/images/misp/blog/mactime2.png) +![SleuthKit mactime import in MISP](https://www.misp-project.org/img/blog/mactime1.png) +![SleuthKit mactime imported in MISP as objects](https://www.misp-project.org/img/blog/mactime2.png) The API has been improved with many new features such as: diff --git a/_posts/2018-12-06-MISP.2.4.99.released.md b/content/blog/2018-12-06-MISP.2.4.99.released.md similarity index 97% rename from _posts/2018-12-06-MISP.2.4.99.released.md rename to content/blog/2018-12-06-MISP.2.4.99.released.md index bfab79f..684c29b 100755 --- a/_posts/2018-12-06-MISP.2.4.99.released.md +++ b/content/blog/2018-12-06-MISP.2.4.99.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.99 released (aka API/UI fixes and critical security vulnerability fixed) +date: 2018-12-06 layout: post -featured: /assets/images/misp-small.png +banner: /img/blog/misp-small.png --- A new version of MISP ([2.4.99](https://github.com/MISP/MISP/tree/v2.4.99)) has been released with improvements in the UI, API, STIX import and a fixed critical security vulnerability. diff --git a/_posts/2019-01-01-MISP.2.4.100.released.md b/content/blog/2019-01-01-MISP.2.4.100.released.md similarity index 97% rename from _posts/2019-01-01-MISP.2.4.100.released.md rename to content/blog/2019-01-01-MISP.2.4.100.released.md index 1015fb0..1283a17 100755 --- a/_posts/2019-01-01-MISP.2.4.100.released.md +++ b/content/blog/2019-01-01-MISP.2.4.100.released.md @@ -1,14 +1,15 @@ --- title: MISP 2.4.100 released (aka happy new year release) +date: 2019-01-01 layout: post -featured: /assets/images/misp/blog/restsearchbuilder.png +banner: /img/blog/restsearchbuilder.png --- Happy new year! We are so proud of our community which has supported us for the past year and we hope to do even better for 2019. Thanks a lot. A new version of MISP ([2.4.100](https://github.com/MISP/MISP/tree/v2.4.100)) has been released with improvements to the UI, API, import and export along with the addition of a new query builder. -![](/assets/images/misp/blog/restsearchbuilder.png) +![](/img/blog/restsearchbuilder.png) Considering the criticality of being able to accurately define how we query MISP instances in order to feed and integrate with network security devices, endpoint security devices or monitoring tools, we have tried to improve the life of the users tasked with the above duties via a new query builder, available through the REST client interface (REST client below the Event Actions). The query builder provides a simple interface to create your JSON queries used to get the information you truly are interested in back for ingestion in your devices and tools easily. diff --git a/_posts/2019-01-20-MISP.2.4.101.released.md b/content/blog/2019-01-20-MISP.2.4.101.released.md similarity index 95% rename from _posts/2019-01-20-MISP.2.4.101.released.md rename to content/blog/2019-01-20-MISP.2.4.101.released.md index e8cc523..836c032 100755 --- a/_posts/2019-01-20-MISP.2.4.101.released.md +++ b/content/blog/2019-01-20-MISP.2.4.101.released.md @@ -1,20 +1,21 @@ --- title: MISP 2.4.101 released (aka 3 features for free) +date: 2019-01-20 layout: post -featured: /assets/images/misp/blog/tag-collection-creation.png +banner: /img/blog/tag-collection-creation.png --- A new version of MISP ([2.4.101](https://github.com/MISP/MISP/tree/v2.4.101)) has been released with 3 main new features (tag collections, improved tag/galaxy selector and MISP instance caching), along with a host of improvements and bug fixes. ## Tag collections -![](/assets/images/misp/blog/tag-collection-creation.png){:class="img-responsive"} +![](/img/blog/tag-collection-creation.png){:class="img-responsive"} Contextualisation in threat intelligence is one of the key activities when performing analysis and when reviewing or processing information from internal or external sources. The task can be rather tedious, but nevertheless, it's a critical step in ensuring the quality and the information's capacity to be used for automatic processing. MISP 2.4.101 introduces a new concept, in an attempt to improve the "time-to-contextualise" information for users using the platform. Tag collections, a new feature in 2.4.101, aim to allow users to predefine re-usable structures consisting of a set of tags (from taxonomies) along with galaxy information attached. Analysts can use these named collections to quickly classify information with all of the contextualisation labels declared in the collection. This functionality enables anyone using MISP to significantly lower the time it takes to classify information and to ensure that all the pre-defined context related information is attached to an event or attribute. This feature is a first step in opening up the sharing of analysisMISP best practices directly via the platform itself. ## Improved tag/galaxy selector -![](/assets/images/misp/blog/tag-collection.png){:class="img-responsive"} +![](/img/blog/tag-collection.png){:class="img-responsive"} The success of MISP taxonomies and galaxies since their inception has been suffering from a minor but annoying drawback. When we originally designed the user-interfaces of the tag and galaxy systems in MISP, our immediate intent was to handle a rather small set of taxonomies. Since then we have come a long way and thanks to the many excellent contributions we've received from the community, the ugly side-effect of our original design decisions reared its head: adding multiple tags and galaxies has become a tedious chore, especially when trying to contextualise several aspects of the information to be shared, using multiple tags and galaxies. diff --git a/_posts/2019-02-02-MISP.2.4.102.released.md b/content/blog/2019-02-02-MISP.2.4.102.released.md similarity index 93% rename from _posts/2019-02-02-MISP.2.4.102.released.md rename to content/blog/2019-02-02-MISP.2.4.102.released.md index 7c08057..1d3a652 100755 --- a/_posts/2019-02-02-MISP.2.4.102.released.md +++ b/content/blog/2019-02-02-MISP.2.4.102.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.102 released (aka bug fixes and FOSDEM release) +date: 2019-02-02 layout: post -featured: /assets/images/misp/blog/anon-graph.png +banner: /img/blog/anon-graph.png --- A new version of MISP ([2.4.102](https://github.com/MISP/MISP/tree/v2.4.102)) has been released with several fixes, various UI improvements, new types and a praise to the open source community. @@ -12,9 +13,9 @@ A new version of MISP ([2.4.102](https://github.com/MISP/MISP/tree/v2.4.102)) ha Sharing and exchanging information encompasses a lot of different models, communities or practices, with the MISP project being involved in various discussions and projects centered around building sharing and information exchange communities. A complex topic comes up regularly, namely the anonymisation of the information exchanged. Sharing anonymised information often aims to simply share the existence of knowledge about information. We introduced a new attribute type in MISP called "anonymised", which can be combined with a newly introduced object called [anonymisation](https://www.misp-project.org/objects.html#_anonymisation). -![](/assets/images/misp/blog/anon-graph.png){:class="img-responsive"} -![](/assets/images/misp/blog/anon2.png){:class="img-responsive"} -![](/assets/images/misp/blog/anonymisation.png){:class="img-responsive"} +![](/img/blog/anon-graph.png){:class="img-responsive"} +![](/img/blog/anon2.png){:class="img-responsive"} +![](/img/blog/anonymisation.png){:class="img-responsive"} The design is flexible and can be extended with new anonymisation techniques and/or approaches. We are standing on the shoulders of giants, for example open source tools such as [Crypto-PAn](https://www.cc.gatech.edu/computing/Networking/projects/cryptopan/), [ipsumpdump](https://github.com/kohler/ipsumdump) or [arx](https://arx.deidentifier.org/). @@ -25,7 +26,7 @@ The open source NIDS [Bro project was renamed Zeek](https://blog.zeek.org/2018/1 ## Sighting -![](/assets/images/misp/blog/sighting-UI.png){:class="img-responsive"} +![](/img/blog/sighting-UI.png){:class="img-responsive"} - MISP UI has been improved to allow sighting at the attribute level or at the global level. - Various improvements to the sighting hover such as a generic hovering support. diff --git a/_posts/2019-03-04-MISP.2.4.103.released.md b/content/blog/2019-03-04-MISP.2.4.103.released.md similarity index 97% rename from _posts/2019-03-04-MISP.2.4.103.released.md rename to content/blog/2019-03-04-MISP.2.4.103.released.md index dfa8863..179f280 100755 --- a/_posts/2019-03-04-MISP.2.4.103.released.md +++ b/content/blog/2019-03-04-MISP.2.4.103.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.103 released (aka UI improvements) +date: 2019-03-04 layout: post -featured: /assets/images/misp/blog/filtering.png +banner: /img/blog/filtering.png --- A new version of MISP ([2.4.103](https://github.com/MISP/MISP/tree/v2.4.103)) has been released with significant UI improvements (including a new flexible attribute filtering tool at the event level), many bug fixes and a fix to a security vulnerability (CVE-2019-9482) which was affecting sighting visibility. @@ -12,9 +13,9 @@ A new version of MISP ([2.4.103](https://github.com/MISP/MISP/tree/v2.4.103)) ha A new attribute filtering tool has been added to the event view to replace the previous filtering. Complex filtering rules can be set to easily filter, navigate and paginate over large events with many attributes and objects. -![MISP screenshot - new attribute filtering tool at event level](/assets/images/misp/blog/filtering.png){:class="img-responsive"} +![MISP screenshot - new attribute filtering tool at event level](/img/blog/filtering.png){:class="img-responsive"} -![MISP screenshot - new attribute filtering tool at event level](/assets/images/misp/blog/filtering2.png){:class="img-responsive"} +![MISP screenshot - new attribute filtering tool at event level](/img/blog/filtering2.png){:class="img-responsive"} ## Improved hover behavior for expansion services. diff --git a/_posts/2019-03-26-MISP.2.4.104.released.md b/content/blog/2019-03-26-MISP.2.4.104.released.md similarity index 94% rename from _posts/2019-03-26-MISP.2.4.104.released.md rename to content/blog/2019-03-26-MISP.2.4.104.released.md index 8706ce6..a897daf 100644 --- a/_posts/2019-03-26-MISP.2.4.104.released.md +++ b/content/blog/2019-03-26-MISP.2.4.104.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.104 released (aka too many new features) +date: 2019-03-26 layout: post -featured: /assets/images/misp/blog/distribution-graph.png +banner: /img/blog/distribution-graph.png --- A new version of MISP ([2.4.104](https://github.com/MISP/MISP/tree/v2.4.104)) has been released with a host of new features such as new overlap feed comparator, a new graph visualisation of event and attribute distributions, a history/bookmark system for the REST client and many others. @@ -12,20 +13,20 @@ A new version of MISP ([2.4.104](https://github.com/MISP/MISP/tree/v2.4.104)) ha Cached feeds can now be compared to the entire set or a subset of the other cached feeds, assisting users in their decision making process for acquiring new feeds based on being able to cover the contents of the new feed with their combination nof existing ingested feeds. -![Comparing a MISP feed to other feeds and check its coverage](/assets/images/misp/blog/feed-coverage.png) +![Comparing a MISP feed to other feeds and check its coverage](/img/blog/feed-coverage.png) ## Distribution graph A new distribution visualisation graph has been introduced to quickly display the potential recipients of the data. This allows users to get an overview of how far events and attributes will be distributed and shows the members of the community who will receive the information shared. -![MISP distribution graph example](/assets/images/misp/blog/distribution-graph.png) +![MISP distribution graph example](/img/blog/distribution-graph.png) ## Bookmark and history in REST client The MISP UI REST Client now keeps a history of the 10 most recently performed queries. Additionally, queries can now be recalled and bookmarked for later use, so there's no longer a need to manually keep track of your queries in your notes, it's now in your MISP instance. -![MISP REST Client bookmarks](/assets/images/misp/blog/rest-bookmarks.png) +![MISP REST Client bookmarks](/img/blog/rest-bookmarks.png) ## Required taxonomy diff --git a/_posts/2019-03-28-MISP.2.4.105.released.md b/content/blog/2019-03-28-MISP.2.4.105.released.md similarity index 96% rename from _posts/2019-03-28-MISP.2.4.105.released.md rename to content/blog/2019-03-28-MISP.2.4.105.released.md index fc58c73..ce46a6c 100644 --- a/_posts/2019-03-28-MISP.2.4.105.released.md +++ b/content/blog/2019-03-28-MISP.2.4.105.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.105 released (aka security fix for CVE-2019-10254) +date: 2019-03-28 layout: post -featured: /assets/images/misp/blog/distribution-graph.png +banner: /img/blog/distribution-graph.png --- A new version of MISP ([2.4.105](https://github.com/MISP/MISP/tree/v2.4.105)) has been released to fix a security vulnerability ([CVE-2019-10254](https://cve.circl.lu/cve/CVE-2019-10254)) in addition to some minor improvements and a fix for the STIX 1.1 import, enabling the import of files with additional namespaces (such as [CISCP](https://www.dhs.gov/cisa/cyber-information-sharing-and-collaboration-program-ciscp)). diff --git a/_posts/2019-04-25-MISP.2.4.106.released.md b/content/blog/2019-04-25-MISP.2.4.106.released.md similarity index 98% rename from _posts/2019-04-25-MISP.2.4.106.released.md rename to content/blog/2019-04-25-MISP.2.4.106.released.md index e7b97e8..1063554 100644 --- a/_posts/2019-04-25-MISP.2.4.106.released.md +++ b/content/blog/2019-04-25-MISP.2.4.106.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.106 released (aka Too many improvements) +date: 2019-04-25 layout: post -featured: /assets/images/misp/blog/graph-thumb.png +banner: /img/blog/graph-thumb.png --- A new version of MISP ([2.4.106](https://github.com/MISP/MISP/tree/v2.4.106)) has been released with a host of improvements, including new features such as a feed cache search, CLI tools to manage your MISP instance along with improved diagnostics. diff --git a/_posts/2019-05-13-MISP.2.4.107.released.md b/content/blog/2019-05-13-MISP.2.4.107.released.md similarity index 98% rename from _posts/2019-05-13-MISP.2.4.107.released.md rename to content/blog/2019-05-13-MISP.2.4.107.released.md index 1c01cd5..aac677e 100644 --- a/_posts/2019-05-13-MISP.2.4.107.released.md +++ b/content/blog/2019-05-13-MISP.2.4.107.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.107 released (aka similar objects review, yara native export) +date: 2019-05-13 layout: post -featured: /assets/images/misp/blog/similar-objects.png +banner: /img/blog/similar-objects.png --- A new version of MISP ([2.4.107](https://github.com/MISP/MISP/tree/v2.4.107)) has been released with a host of new features, improvements and security fixes. We strongly advise all users to update their MISP installation to this latest version. diff --git a/_posts/2019-06-05-MISP.2.4.108.released.md b/content/blog/2019-06-05-MISP.2.4.108.released.md similarity index 98% rename from _posts/2019-06-05-MISP.2.4.108.released.md rename to content/blog/2019-06-05-MISP.2.4.108.released.md index f51e2e8..e1c7184 100644 --- a/_posts/2019-06-05-MISP.2.4.108.released.md +++ b/content/blog/2019-06-05-MISP.2.4.108.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.108 released (aka copy-paste-and-sync feature) +date: 2019-06-05 layout: post -featured: /assets/images/misp/blog/anothergraph.png +banner: /img/blog/anothergraph.png --- A new version of MISP ([2.4.108](https://github.com/MISP/MISP/tree/v2.4.108)) has been released with a host of new features, improvements and bugs fixed. We strongly advise all users to update their MISP installations to this latest version. diff --git a/_posts/2019-06-14-MISP.2.4.109.released.md b/content/blog/2019-06-14-MISP.2.4.109.released.md similarity index 94% rename from _posts/2019-06-14-MISP.2.4.109.released.md rename to content/blog/2019-06-14-MISP.2.4.109.released.md index dee5861..ad2479e 100644 --- a/_posts/2019-06-14-MISP.2.4.109.released.md +++ b/content/blog/2019-06-14-MISP.2.4.109.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.109 released (aka cool-attributes-to-object) +date: 2019-06-14 layout: post -featured: /assets/images/misp/blog/attribute-to-object.gif +banner: /img/blog/attribute-to-object.gif --- # MISP 2.4.109 released @@ -12,14 +13,14 @@ A new version of MISP ([2.4.109](https://github.com/MISP/MISP/tree/v2.4.109)) ha ## Encapsulate existing attributes into an object -![](https://www.misp-project.org/assets/images/misp/blog/attribute-to-object.gif) +![](https://www.misp-project.org/img/blog/attribute-to-object.gif) When an analyst inserts information into MISP, it's very common to start with a set of unstructured indicators/attributes. At a later stage, common structures emerge and combining attributes into objects start making more and more sense. However, the effort spent on the process of attribute creation would have to be repeated in prior versions via the object creation interface, something that resulted in analysts deciding to save time and effort and move on, leaving the unstructured data as is. To reduce the workload needed to bring structure to our prior work, we have now introduced a new feature, allowing users to easily select a set of attributes and automatically propose suitable object templates depending on the combination of types of the selected attributes. These in turn, can be gathered and processed into the desired object. ## Improved ATT&CK and ATT&CK-like matrix support -![](https://www.misp-project.org/assets/images/misp/blog/attack-new.png) -![](https://www.misp-project.org/assets/images/misp/blog/fraud-tactics.png) +![](https://www.misp-project.org/img/blog/attack-new.png) +![](https://www.misp-project.org/img/blog/fraud-tactics.png) We received exhaustive feedback during the FIRST.org CTI conference in London and the [ATT&CK EU community](https://www.attack-community.org/) workshop at Eurocontrol concerning the ATT&CK integration in MISP. The matrix visualisation has been improved by sorting and reorganising the individual techniques based on their aggregate scores. These statistics can now easily be queried based on time-ranges, organisations, tags, along with all other restSearch enabled filters to generate ATT&CK like matrix views. diff --git a/_posts/2019-07-08-MISP.2.4.110.released.md b/content/blog/2019-07-08-MISP.2.4.110.released.md similarity index 94% rename from _posts/2019-07-08-MISP.2.4.110.released.md rename to content/blog/2019-07-08-MISP.2.4.110.released.md index 2f29023..3c2b0b7 100644 --- a/_posts/2019-07-08-MISP.2.4.110.released.md +++ b/content/blog/2019-07-08-MISP.2.4.110.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.110 released (aka local-tags and new MISP modules supporting MISP standard format) +date: 2019-07-08 layout: post -featured: /assets/images/misp/blog/modules-expand.gif +banner: /img/blog/modules-expand.gif --- # MISP 2.4.110 released @@ -14,12 +15,12 @@ A new version of MISP ([2.4.110](https://github.com/MISP/MISP/tree/v2.4.110)) ha [misp-modules](https://github.com/MISP/misp-modules) now support MISP objects and relationships. The revamped system is still compatible with the old modules, whilst the new modules bolster up the complete MISP standard format. New modules such as [url-haus](https://github.com/MISP/misp-modules/blob/52dadd2df32b19241fdd978e50b717f1967e264b/misp_modules/modules/expansion/urlhaus.py), [joe sandbox query](https://github.com/MISP/misp-modules/blob/be61613da4f5dc8f082a7c1a9e1ec07fdb872560/misp_modules/modules/expansion/joesandbox_query.py) and many others support the new MISP standard format. This new feature allows module developers to create more advanced modules, generating MISP objects and associated relationships from any type of expansion, import or export modules in one click. -![](https://www.misp-project.org/assets/images/misp/blog/misp-modules-new.png) -![](https://www.misp-project.org/assets/images/misp/blog/misp-modules-2.png) +![](https://www.misp-project.org/img/blog/misp-modules-new.png) +![](https://www.misp-project.org/img/blog/misp-modules-2.png) ## Local tags introduced -![](https://www.misp-project.org/assets/images/misp/blog/local-tags.png) +![](https://www.misp-project.org/img/blog/local-tags.png) The long awaited feature "local tags" is now finally available. You can create tags locally if you are a member of the given MISP instance's host organisation, enabling "in-place" tagging for synchronisation and export filtering. MISP events are not modified while using the local tags and are in turn always stripped before being synchronised with other MISP instances and sharing communities. Local tags allow users to avoid violating the ownership model of MISP, but still be able to tag any event or attribute for further dissemination and data contextualisation. Local tagging works for tags, tag collections, galaxies and matrix-like galaxies such as ATT&CK. diff --git a/_posts/2019-07-19-MISP.2.4.111.released.md b/content/blog/2019-07-19-MISP.2.4.111.released.md similarity index 98% rename from _posts/2019-07-19-MISP.2.4.111.released.md rename to content/blog/2019-07-19-MISP.2.4.111.released.md index 3d3736e..13d9c98 100644 --- a/_posts/2019-07-19-MISP.2.4.111.released.md +++ b/content/blog/2019-07-19-MISP.2.4.111.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.111 released (aka improved proposal sync) +date: 2019-07-19 layout: post -featured: /assets/images/misp/blog/comid.jpeg +banner: /img/blog/comid.jpeg --- # MISP 2.4.111 released diff --git a/_posts/2019-08-01-MISP.2.4.112.released.md b/content/blog/2019-08-01-MISP.2.4.112.released.md similarity index 98% rename from _posts/2019-08-01-MISP.2.4.112.released.md rename to content/blog/2019-08-01-MISP.2.4.112.released.md index 5280f00..e5a27a0 100644 --- a/_posts/2019-08-01-MISP.2.4.112.released.md +++ b/content/blog/2019-08-01-MISP.2.4.112.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.112 released (aka summer fixes and improvement) +date: 2019-08-01 layout: post -featured: /assets/images/misp/blog/vuln.png +banner: /img/blog/vuln.png --- # MISP 2.4.112 released diff --git a/_posts/2019-08-19-MISP.2.4.113.released.md b/content/blog/2019-08-19-MISP.2.4.113.released.md similarity index 99% rename from _posts/2019-08-19-MISP.2.4.113.released.md rename to content/blog/2019-08-19-MISP.2.4.113.released.md index 0c6a6eb..893b79e 100644 --- a/_posts/2019-08-19-MISP.2.4.113.released.md +++ b/content/blog/2019-08-19-MISP.2.4.113.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.113 released (aka the bugs fixing marathon) +date: 2019-08-19 layout: post -featured: /assets/images/misp/blog/matrix.jpg +banner: /img/blog/matrix.jpg --- # MISP 2.4.113 released diff --git a/_posts/2019-08-31-MISP.2.4.114.released.md b/content/blog/2019-08-31-MISP.2.4.114.released.md similarity index 99% rename from _posts/2019-08-31-MISP.2.4.114.released.md rename to content/blog/2019-08-31-MISP.2.4.114.released.md index d00906f..05d25d8 100644 --- a/_posts/2019-08-31-MISP.2.4.114.released.md +++ b/content/blog/2019-08-31-MISP.2.4.114.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.114 released (aka the community care package release) +date: 2019-08-31 layout: post -featured: /assets/images/misp/blog/community-view.png +banner: /img/blog/community-view.png --- diff --git a/_posts/2019-09-10-MISP.2.4.115.released.md b/content/blog/2019-09-10-MISP.2.4.115.released.md similarity index 99% rename from _posts/2019-09-10-MISP.2.4.115.released.md rename to content/blog/2019-09-10-MISP.2.4.115.released.md index 6a97d9d..214ac24 100644 --- a/_posts/2019-09-10-MISP.2.4.115.released.md +++ b/content/blog/2019-09-10-MISP.2.4.115.released.md @@ -1,7 +1,8 @@ --- title: MISP 2.4.115 released (aka CVE-2019-16202 and sync speed improvement) +date: 2019-09-10 layout: post -featured: /assets/images/misp/blog/community-view.png +banner: /img/blog/community-view.png --- # MISP 2.4.115 released diff --git a/_posts/2019-09-12-Decaying-Of-Indicators.md b/content/blog/2019-09-12-Decaying-Of-Indicators.md similarity index 86% rename from _posts/2019-09-12-Decaying-Of-Indicators.md rename to content/blog/2019-09-12-Decaying-Of-Indicators.md index 4586f87..0daefaa 100644 --- a/_posts/2019-09-12-Decaying-Of-Indicators.md +++ b/content/blog/2019-09-12-Decaying-Of-Indicators.md @@ -1,7 +1,8 @@ --- title: Decaying of Indicators - MISP improved model to expire indicators based on custom models +date: 2019-09-12 layout: post -featured: /assets/images/misp/blog/decay.png +banner: /img/blog/decay.png --- # An improved and flexible model to expire indicators @@ -36,9 +37,9 @@ We still have to see how the ``base_score`` is actually computed. In the current To give the intuition of how the ``base_score`` computation works, let's look at two examples. In these examples, the two *Taxonomies* used are [*phishing*](https://github.com/MISP/misp-taxonomies/blob/master/phishing/machinetag.json) and [*admiralty-scale*](https://github.com/MISP/misp-taxonomies/blob/master/admiralty-scale/machinetag.json). Both of them contain *Tags* that have a ``numerical_value`` associated to them: -- admiraly-scale:source-reliability = Completely reliable, ``numerical_value = 100`` -- admiraly-scale:source-reliability = Not usually reliable, ``numerical_value = 25`` -- phishing:psychological-acceptability = high, ``numerical_value = 75`` +- admiraly-scale:source-reliability = Completely reliable, ``numerical_value = 100`` +- admiraly-scale:source-reliability = Not usually reliable, ``numerical_value = 25`` +- phishing:psychological-acceptability = high, ``numerical_value = 75`` So, if an *Attribute* only has a single *Tag* attached, for example ``admiralty-scale:source-reliability="Completely reliable"``, the ``base_score`` would be: ``` @@ -53,9 +54,9 @@ phishing = 50 --------------------- sum 100 ``` -If an *Attribute* has the *Tags* admiraly-scale:source-reliability = Completely reliable and phishing:psychological-acceptability = high attached, the computation steps would look like this: +If an *Attribute* has the *Tags* admiraly-scale:source-reliability = Completely reliable and phishing:psychological-acceptability = high attached, the computation steps would look like this: -![base_score computation steps](/assets/images/misp/blog/decaying/bs-computation-steps.png) +![base_score computation steps](/img/blog/decaying/bs-computation-steps.png) Thus, the ``base_score`` of this *Attribute* will be ``87.50``. @@ -70,7 +71,7 @@ Now that we've seen the basic concepts, let's have a look at how MISP implements At the *Event* level, a new filter button has been added, which attaches the real-time computed ``score`` to all *Attributes* that have been mapped to a *Model*. -Decay Model index +Decay Model index ### Endpoint: ``attribute/restSearch`` @@ -109,19 +110,19 @@ When creating a new *Decaying Model*, modifying its parameters and viewing the o ### Customising the lifetime and the decay speed parameters -