Where communities thrive


  • Join over 1.5M+ people
  • Join over 100K+ communities
  • Free without limits
  • Create your own community
People
Activity
  • Jan 31 21:52
    zpriddy edited #860
  • Jan 31 21:52
    zpriddy opened #860
  • Jan 31 14:03
    adl1995 opened #165
  • Jan 31 13:56
    nadouani closed #769
  • Jan 31 13:55

    nadouani on develop

    #769 Add a case template select… Merge branch 'feature/template-… #769 Add case template selector (compare)

  • Jan 31 13:55
    nadouani commented #769
  • Jan 31 13:54
    nadouani milestoned #769
  • Jan 30 18:41
    amr-cossi opened #164
  • Jan 30 16:21
    nadouani edited #271
  • Jan 30 16:20

    nadouani on develop

    #271 Allow merging multiple ale… (compare)

  • Jan 30 16:18

    To-om on develop

    #271 Update alert status when m… (compare)

  • Jan 30 15:53

    To-om on develop

    #271 Add API to merge alert in … (compare)

  • Jan 30 10:44
    nadouani closed #857
  • Jan 30 10:44
    nadouani labeled #857
  • Jan 30 10:44
    Xumeiquer commented #857
  • Jan 30 10:30
    nadouani edited #271
  • Jan 30 10:30
    nadouani edited #271
  • Jan 30 10:30
    nadouani edited #271
  • Jan 30 10:30
    nadouani edited #271
cyberpescadito
@cyberpescadito
never noticed such behaviour :/
3GR4
@3GR4
Does anyone get server CPUs consumed when opening TheHive using firefox
And then he have to kill process forcefully
Michael
@ag-michael
@3GR4 never had to, best to open an issue :)
Frikkylikeme
@frikky
Heyo, just want to say that I made a PDF report generator for thehive cases https://github.com/frikky/hive-case-report. Its not really that good, but has enough functionality to satisfy whoever needs it at my current job :^)
cyberpescadito
@cyberpescadito
@frikky amazing! thanks for sharing !
tr0mb1r
@tr0mb1r
Hello all! I want to make a responder for observable, what list of fields are available via get_param()?
josarsepi
@josarsepi

Issues with migration between 3.2 and 3.3 releases:

info] play.api.Play - Application started (Prod)
[info] p.c.s.AkkaHttpServer - Enabling HTTP/2 on Akka HTTP server...
[info] p.c.s.AkkaHttpServer - Listening for HTTP on /0:0:0:0:0:0:0:0:9000
migrateEntity(action) has finished : Success(())
migrateEntity(sequence) has finished : Success(())
migrateEntity(dblist) has finished : Success(())
migrateEntity(caseTemplate) has finished : Success(())
migrateEntity(dashboard) has finished : Success(())
migrateEntity(user) has finished : Success(())
migrateEntity(reportTemplate) has finished : Success(())
migrateEntity(case_task) has finished : Success(())
migrateEntity(case_task_log) has finished : Success(())
migrateEntity(data) has finished : Success(())
migrateEntity(alert) has finished : Success(())
migrateEntity(case_artifact_job) has finished : Success(())
migrateEntity(case_artifact) has finished : Failure(org.elastic4play.SearchError: Request terminated early or timed out)
migrateEntity(audit) has finished : Failure(org.elastic4play.SearchError: Request terminated early or timed out)
migrateEntity(case) has finished : Failure(org.elastic4play.SearchError: Request terminated early or timed out)

Has anyone else experienced this? Is there a way to continue the migration?

ramocha
@ramocha
Hi all! i'm need to know if someone can tell me if exist an analyzer/responder to check the header of an email
Fabien B.
@softybear
Hi @tr0mb1r, in order to retrieve observable, I retrieve the case ID via get_param() and then I query http://hive_url/api/case/artifact/_search and filter using retrieved case_ID, and then I can retrieve specific observables and values :)
tr0mb1r
@tr0mb1r
@softybear yes, but i made it through thehive4py, get_param('data._parent') - getting _id of case and then api.get_case(parentId).json()['caseId']
thank you
xanster
@xanster
Hi guys is there a way for an analyzer to retrieve the tags of a case without any criteria aside from the caseID of the observable?
I've tried hive4py but it requires an input of what to search which is not possible from the analyzer side.
Jeffrey E
@gekkeharry13
hi @ramocha you can use the emlparser analyzer for that if you mean by checking that you want to have it present in the case.
Toby Lerone
@TLerone79_twitter
Anyone have any real-world guidance on what the spec of the Hive/Cortex server should be ?
L I T T L 3 F I E L D
@littl3field
Hi people, we have a problem with MISP alerts, it seems that alerts are only coming through when theHive service is restarted, has anybody else encountered this
Son of grep
@co2underground_twitter
While at DefCon I talked to someone from TheHive-Project. Cant find his business card but interested in talking more. Anyone from hive in this room?
ramocha
@ramocha
Hi @gekkeharry13 thanks but the emlparser dont read msg files but i will see the code to find what do.
Michael
@ag-michael
does anyone know how to set Xms and Xmx for thehive so that I can control heap memory usage?
Michael
@ag-michael
nvm, I figured it out, you just add -J-Xms7g -J-Xmx7g or something in the unit file :)
Devin Ferguson
@devinbfergy
@ag-michael does the hive do a base setting that you can see?
@ag-michael I have never seen a unit file.
Jeffrey E
@gekkeharry13
@ramocha if you use synapse to import E-mails, it will convert them to eml from msg.So that might help you out :)
ramocha
@ramocha
@gekkeharry13 oh greate i'll investigate that. Thanks
Michael
@ag-michael
@devinbfergy it does, I think it was set to 1GB , unit files are what you use to start/stop a service in a systemd environment
Devin Ferguson
@devinbfergy
@ag-michael Oh makes sense. I am using docker so I didn't even think about them as running as a service.
Devin Ferguson
@devinbfergy
I will have to see where that is being setup so it will better utilize resources.
Gabriel
@mgabriel-silva
Hello. Do any of you know a way to search all artifacts (observables) from case and alert?
I need to confirm if some observables are already created both in cases and alerts
Dilaw9
@Dilaw9
Hi people, has any of you tried to use a dockerized custom analyzer/responder inside a dockerized Cortex ? I have some trouble understanding how to do that.
k41zen
@k41zen
hey all, anyone know if its possible to add a TLP colour to an observable type? we've added an internal observable for us to track access to a system and wouldn't want it being analysed externally. Would be good for it to pre-populate the tags/tlp level based on the observable type chosen
L I T T L 3 F I E L D
@littl3field
Hey guys, how do you enable the Mailer Responder in Cortex?
Can't see any details on this in the documentation
Matthias Schulz
@masulz
Hello. I built TheHive from Source and followed the steps. I finished the ./sbt clean stage and copied the compiled files to /opt How do I start TheHive now?
Josh Brower
@defensivedepth
Looking for an idea of how TheHive handles large amounts of unread Alerts (from a performance perspective)? Anybody handled more than a couple thousand unread Alerts?
Michael
@ag-michael
@defensivedepth I have done that with issues open
I have it working OK now with my alert deletion (old alert) script
It's not horrible but things slow down a bit when I had more than ~5K alerts with some alerts being large (>1MB)
it's not too bad if you can efficiently control the maximum size each alert takes
@littl3field once you found and enabled it in Cortex, you'll need to add the recipients in a tag like mail:someone@corp.com
Michael
@ag-michael
@mgabriel-silva :
image.png
look at the search option at the top of the page, you cansearch for 'all' or under observables and cases ,maybe that's what you're looking for?
Josh Brower
@defensivedepth
@ag-michael My assumption is that if you scale the system, that should deal with the slowness? Or do you think it was inherent to how the UI / something else works with that many alerts?
Michael
@ag-michael
@defensivedepth You can scale the backend, but with a large number of alerts I at least ran into odd bugs (e..g.: #1037) which is certainly fixable. The UI itself has limits, I don't think it's the backend being slow most of the time. I did try adding a node to the ES cluster to see if it makes a huge difference, it did make it more responsive but there were things like alerts loading or filtering 15K alerts over a keyword that took 1min+ at times
Josh Brower
@defensivedepth
@ag-michael ok, understood. Can you share what hardware specs you are running with that kind of alert volume?
Also, did you have issues at the volume even with the alerts "ignored"?
Michael
@ag-michael
@defensivedepth I did have issues with the alerts ignored, spec for DB server (dedicated) is 12G ram and 4 cores with ES using 5G
Josh Brower
@defensivedepth
@ag-michael Thanks much!