MISP Install - 1 Million (+) Free IoCs in 10 Minutes!

Поделиться
HTML-код
  • Опубликовано: 8 янв 2025

Комментарии • 35

  • @jackylam5365
    @jackylam5365 2 года назад +5

    Hi, For "Scheduled Tasks", it need to start the "scheduler" work first. Navigate to "Administrator" -> "Server Settings & Maintenance" -> "Workers" tab and scroll down to "Worker type: scheduler". If no worker, just start a new worker. If it is "dead", kill it and start a new. This is let "Scheduled Tasks" works like schedule fetch feeds, etc. Remember to set "Frequency" to 1-24. Hope it helps

  • @Foxi352
    @Foxi352 2 года назад +6

    Great content, as is the whole series. I think there is no need to import the feed json. Clicking the "Load default feed metadata" button should do the same afaik.

  • @cyrilokonkwo3323
    @cyrilokonkwo3323 7 месяцев назад +2

    For some reason, I've been unable to actually start using MISP after deployment, because the documentation and training I've seen so far is just not usable for beginners. Is there any other training that can be leveraged?

  • @vinyldown8490
    @vinyldown8490 Год назад +1

    what an amazing series. Thanks

  • @monkinsane
    @monkinsane 11 месяцев назад

    Awesome man!!
    MISP docker container build failed for me for some reason. (Ubuntu 22.04)
    I just installed on base machine instead (no docker) - that worked perfectly. Thanx for the hard work on these tutorials. Fantastic content.

    • @Trabalhopbworks
      @Trabalhopbworks 11 месяцев назад

      Can you help me?? Did you started with the oficial MISP documentation on github??

    • @monkinsane
      @monkinsane 11 месяцев назад

      @@Trabalhopbworks RUclips keeps deleting my reply to you. Yes I used the install script.

    • @monkinsane
      @monkinsane 11 месяцев назад

      Just be aware that both Wazuh Dashboard and MISP uses the same port by default - you'll need to change one of them to a different one.

  • @riyasachan8500
    @riyasachan8500 11 месяцев назад

    I am using docker-compose pull then docker-compose up -d but web page is not accessible.
    I am using digital ocean .
    Please give your suggestions.

  • @praveenpatil6687
    @praveenpatil6687 Год назад +1

    Dear Taylor, could you please help me with the below questions, thank you
    1.Once we deploy MISP as a stand-alone, Where to link MISP to monitor alerts? SIEM/SOAR or EDR , LDAP , AWS or any other? (In other words: If I deploy MISP in server, how does it look for threats in our environment, what logs does it to need to check, what should I link MISP to AWS? LDAP? Any other? To check all the machines)
    2.Do MISP gather information from various OSINT tools and compare the risk/threat in our environment ?

  • @barryabrams6071
    @barryabrams6071 Год назад +1

    Has anyone installed MISP Container on Docker using an AWS EC2 Instance loaded with Ubuntu Version 22.04? I have tried this with CoolAcid misp-docker and Harvard-itsecurity/docker-misp. I checked to ensure everything is installed, up, and running but I can't connect to the MISP Login Page with localhost, IP Address, or Port Number. I have noticed MySQL is not up and running. Should I edit this with a new IP or port number? If so, what file should I edit?

    • @monkinsane
      @monkinsane 11 месяцев назад

      Mine wouldn't even build the docker for MISP on Ubuntu 22.04
      I ended up installing it barebones on the machine via installer script from github (compiling from source) - maybe give that a try.

    • @Trabalhopbworks
      @Trabalhopbworks 11 месяцев назад

      Can you explain better?? i am with version 22.04, How Can I start?? ​@@monkinsane

  • @batista98854
    @batista98854 2 года назад +2

    Awesome. Thanks from India. Please make more videos on misp and hive 👍

  • @johnbaby3763
    @johnbaby3763 5 месяцев назад +1

    Does this still works, if I follow the steps?

    • @syedkashif5604
      @syedkashif5604 4 месяца назад

      I'm making a home lab will let you know if it works :D or you can help me if you have done the installation?

    • @architvats2633
      @architvats2633 2 месяца назад

      It doesn't look like it's still working. The .env file doesn't have the right content. Even putting the content as shown in the video would break the docker compose command

  • @aimanilyasa4365
    @aimanilyasa4365 Год назад +1

    what CLI is he using?

  • @ServusChristi777
    @ServusChristi777 Год назад

    Why when I have added the feeds am I only seeing events up to 2016? Are these providers not putting data anymore?

  • @FlLn-e9x
    @FlLn-e9x Год назад

    Hey there great content, thanks for your efforts.
    Quick question: Downloaded MISP from GitHub as per your video on Linux box, decided to run Defender scan which triggered malware alerts on 6 files, 3 of which are in tests folder.
    Did you also face this issue? Wanted to know if this MISP app is safe for production usage
    Many thanks

  • @amirsohail1704
    @amirsohail1704 Год назад +1

    I am running the script from the root user, are not running the script. Why please help me

  • @dakshkalucha5408
    @dakshkalucha5408 Год назад +1

    docker build is taking very long for me. It has taken 1 hour and still counting.....
    Took 1.5 hours and 3GB internet data to complete :)

  • @wispyara
    @wispyara Год назад

    You explained how to get attributes and etc. from MISP, am I right?

  • @johnchong9660
    @johnchong9660 Год назад

    How to update the feeds as my feeds was old

  • @SyuneKyureghyan
    @SyuneKyureghyan Год назад

    Hi everyone, I need help how can I configure my mail server, how can I send mails?

  • @PatrickKelley-g3v
    @PatrickKelley-g3v Год назад

    Anyone build MISP on Oracle 8 successfully? I am trying to accomplish this on an Oracle 8 server but cannot find much online

  • @calvinnguyen1699
    @calvinnguyen1699 Год назад

    do you have course for Cysa+

  • @zer-kz8mb
    @zer-kz8mb 2 года назад

    MISP is great osint tool but it is not the end all be all.