Skip to content

Latest commit

 

History

History
 
 

README.md

fir_misp

This plugin leverages the MISP Threat Intelligence platform in order to enrich incidents. When opening an incident, a "MISP" tab will display all known observables and indicators matching your incident's artifacts, as well as related events.

You can also send your artifacts to MISP directly from FIR.

Features

  • Push FIR artifacts to MISP.
  • Display data from MISP into FIR cases. (automatic search)

Requirements

  • Python 3.7+
  • pymisp library (pip install pymisp)
  • Access to a running MISP instance with a valid API key

Install

First, follow the generic plugin installation instructions in the FIR wiki.

Then, each user needs to set his MISP API key and the location of the MISP instance in his profile page (by clicking on his username). Alternatively, an administrator you can also set up the API key and location globally, by defining the settings MISP_URL and MISP_APIKEY in FIR config.

Custom CA file

HTTPS requests to MISP are made using python requests, which check for certificate validity using certifi. Thus, if your MISP instance has a custom or self-signed CA you need to add it to the certifi list in order to avoid certificate errors.

You can find the location of this list on your system with the command python3 -m requests.certs. On Debian/Ubuntu, the certifi list can be found at /etc/ssl/certs/ca-certificates.crt

User manual

At the bottom of the ticket details page, you can find a "MISP" tab. Here, you can find information about the ticket artifacts that are attached to a MISP event.

qqOCmLPfxo8k31dL-image

Here you can find the details about MISP related events (MISP event with fir-incident & fir-<incident_id> tags), and MISP observables, the tags attached & description.

/!\ If an artifact is related to several misp event, only the most recent one is displayed.

On the MISP tab, if you see the message "No intelligence available for this incident. Please check your configuration settings", wait : it can be because the ticket has many artifacts attached and the MISP search is still running. If the message persists, ask a fir admin to configure a MISP api key for you : yCPGmMmGOYyRQmOs-image

These buttons redirect you directly to the right MISP event : tWXfBAiFqoQEQ2Bn-image

The "unknown observable" list allows you to visualize the fir observable that are unknown in MISP : Os1ozJ9xxbtm4Dwo-image

At the bottom of the list, you have a button to send new artifacts / add tags to MISP :

image

When you hit this button, you see a first panel containing the misp events related to your fir case : bKjFmp9Pt1p2l6R3-image

Here, you can check the misp event you want to link to the observables. If no event is checked, it will create a new event, with the tags fir-incident, and fir-< your case id >

Under this panel, you have the observables panel, where you can select all the observables you want to add. You can also attach tags to those observables, either if the observable is newly sent to misp or if it does already exist. (you can't remove tags that already exists on misp side, if the observable is already linked to the misp event)

To add a tag, click on "+" and type the tags you want to add, and type enter 9aVnrQJwSB0dxGgs-image

For example, here I will add the tag "test" when I will send the form : 00ZYQnEXzeDFoYnP-image

If you want to correct the tag you just typed, just hover the tag and click on the garbage can : NProOL7lt9qftWDk-image

This button shows you some tags suggestions : G9r4P2cZxOLGjKNF-image

Just click on a suggestion to add it to the tags to attach to the observable : p0BA6uJ1f1huJHqN-image

At the end of the form, you have a field where you can add tags who will be added to all observables send to misp : aW3Ayq7okXgSXIAo-image

When you are happy with the form content, you can sent it by clicking the "Send it!" button :

Q3NmjYtTy3rPNJap-image

/!\ If no observable is checked, nothing will be done, you have to check at least one observable to send data to MISP

License

This module inherits the FIR license (GNU GPLv3).