TheHive, Cortex & MISP Installation Using Docker Compose - Virtual Lab Building Series: Ep10

Опубликовано: 16 Июнь 2022
на канале: LS111 Cyber Security Education
31,607
440

Hey all and welcome to my channel! In Episode 10 of our cyber security virtual lab building series, we are going to install TheHive, Cortex and MISP using Docker containers by leveraging the Docker Compose tool and using .YAML to define our deployment.

To recap, TheHive is a security incident response platform (SIRP) used by cyber security professionals to manage and track incidents on a case by case basis. Cortex and MISP are platforms that provide us with intelligence after analysis of any observables such as IP addresses, hostnames etc that we may see during the incident.

There are many approaches to installing these platforms, however, for a quick and easy lab setup I have chosen to deploy docker containers for each service.

This is part 1 of the installation, stay tuned, in the next video session I will complete all the integrations of these platform as well as be revisiting Wazuh that we installed in the previous video, integrating it with these systems.

If you have been enjoying this series so far, please don't forget to like and subscribe!

Links used in video:
https://www.docker.com/resources/what...
https://docs.docker.com/compose/
https://github.com/coolacid/docker-misp
https://hub.docker.com/r/strangebee/t...
https://hub.docker.com/_/redis
https://hub.docker.com/_/cassandra
https://hub.docker.com/_/elasticsearch
https://hub.docker.com/r/thehiveproje...
https://docs.strangebee.com/thehive/s...

****UPDATED DOCKER COMPOSE .YAML****
https://github.com/ls111-cybersec/the...

**OLD VERSION (Incase the changes want to be referenced)**
Docker-Compose Configuration File: https://ls111.me/thehive-cortex-misp-...

NOTE: I am not sponsored by or affiliated to any of the products or services mentioned in this video, all opinions are my own based on personal experiences.

DISCLAIMER: All information, techniques and tools showcased in these videos are for educational and ethical penetration testing purposes ONLY. NEVER attempt to use this information to gain unauthorized access to systems without the EXPLICIT consent of its owners. This is a punishable offense by law in most countries.

#thehive #cortex #docker #misp #cybersecurity #soc