OpenCTI Install - Install Your Own OpenCTI Stack!

แชร์
ฝัง
  • เผยแพร่เมื่อ 20 ธ.ค. 2024

ความคิดเห็น • 81

  • @LJsec
    @LJsec 2 ปีที่แล้ว +5

    Just to help anyone that may come across the same issue:
    I had difficulty with Portainer - it kept dropping the connection. The solution is to restart the portainer service and the portainer agent service. TO do this:
    1. Find the ids of the services using: docker ps command
    2. restart them using: docker restart
    Portainer should then reconnect

  • @dotcaodin
    @dotcaodin 2 ปีที่แล้ว +4

    You have been providing to us nice tutorials.
    Keep up the good work! 🎯

  • @hassanaliraza78
    @hassanaliraza78 2 ปีที่แล้ว +2

    what software u r using as a terminal .

  • @codepirate1975
    @codepirate1975 2 ปีที่แล้ว

    Thanks a ton @OpenSecure for this tutorial. I managed to install OpenCTI on AWS EC2 instances. Cheers!

    • @zuiokopl2256
      @zuiokopl2256 2 ปีที่แล้ว

      Not getting UI while everything went smooth till IP:PORT

    • @openctithreatintel9088
      @openctithreatintel9088 2 ปีที่แล้ว

      @@zuiokopl2256
      same issue here. Did you find any solution?

    • @zuiokopl2256
      @zuiokopl2256 2 ปีที่แล้ว

      @@openctithreatintel9088 hello yes, I'll suggest to check your portainer logs for CTI on my logs there was issue with RAM

  • @BorisJohnsonMayor
    @BorisJohnsonMayor 2 ปีที่แล้ว +1

    What's that terminal session application on the right side called?

  • @armweepatviiix6143
    @armweepatviiix6143 10 หลายเดือนก่อน +2

    I have a Dropping connection on port 8080 , After deploy stack i cant connect to

  • @praveenadithya1790
    @praveenadithya1790 2 ปีที่แล้ว +1

    Amazing stuff.. are there anyways to export opencti data into a SIEM like microsoft sentinel?

  • @bakhtawar9599
    @bakhtawar9599 2 ปีที่แล้ว +1

    Hi, I followed the installation steps but unable to access opencti web ui. Can you please look into this issue? Thanks

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว +1

      Check your redis, elasticsearch, and rabbitmq containers logs to ensure those are first running properly. The OpenCTI platform will not spin up correctly if either of those 3 containers are having issues.

    • @bakhtawar9599
      @bakhtawar9599 2 ปีที่แล้ว +1

      Yes, elastic search seems down. How can it be fixed?

    • @bakhtawar9599
      @bakhtawar9599 2 ปีที่แล้ว

      @@zuiokopl2256 I installed without docker swarm. Instead I went for installation on a single node. That way it works fine.

    • @whotopu
      @whotopu 2 ปีที่แล้ว

      @@bakhtawar9599 if i run this process on a single VM, what will be the open cti IP? AS I used manager IP once that is used as portainer ip.

  • @kageyouth4517
    @kageyouth4517 2 ปีที่แล้ว +2

    quick dumb question what vm are u running?

    • @wecantalkaboutit5312
      @wecantalkaboutit5312 2 ปีที่แล้ว

      he is using docker (docker-compose, swarm, etc)

    • @banano28_oficial
      @banano28_oficial 2 ปีที่แล้ว +1

      @@wecantalkaboutit5312 I think he means the one windows in the right view. I do have the same question.

    • @zuiokopl2256
      @zuiokopl2256 2 ปีที่แล้ว +1

      @@banano28_oficial thats Termius

    • @ollytbh
      @ollytbh 2 ปีที่แล้ว

      @@banano28_oficial I think it's Termius - I googled around as I also wanted to know

  • @banano28_oficial
    @banano28_oficial 2 ปีที่แล้ว

    Hey, thanks a lot for the video and explanations. I managed to install, configure and run in centos minimal.

    • @zuiokopl2256
      @zuiokopl2256 2 ปีที่แล้ว

      Not getting UI while everything went smooth till IP:PORT

    • @banano28_oficial
      @banano28_oficial 2 ปีที่แล้ว

      @@zuiokopl2256 did you check if the docker instance is running? I think the cmd is: docker ps

    • @zuiokopl2256
      @zuiokopl2256 2 ปีที่แล้ว

      @@banano28_oficial Currently it shows like this
      CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
      9bcd3d4ebdd3 portainer/portainer-ce:2.11.1 "/portainer -H tcp:/…" 3 minutes ago Up 3 minutes 8000/tcp, 9000/tcp, 9443/tcp portainer_portainer.1.3ww87et8212z2q3vpjo6cmof2
      9de082c80d8d portainer/agent:2.11.1 "./agent" 14 minutes ago Up 13 minutes portainer_agent.thim6okmfh9lmdv9fp131eczu.kpr2ibr2q1wwqamj1t7bk5tjb

    • @zuiokopl2256
      @zuiokopl2256 2 ปีที่แล้ว

      Can you help please?

  • @zakecysec
    @zakecysec 6 หลายเดือนก่อน +1

    Already follow this tutorial but im stack while open it in browser with port 8080

    • @lelekappaz
      @lelekappaz 5 หลายเดือนก่อน

      I have the same problem :(

  • @frnacisinetum1927
    @frnacisinetum1927 25 วันที่ผ่านมา

    I have a issue with minio container '' it is hunealthy'' I tried to change version but same issues. Do you have a solution please ?

    • @frnacisinetum1927
      @frnacisinetum1927 25 วันที่ผ่านมา

      i try wiht cpuv1, i tried the two latest...

  • @mrbigglesworth_Official
    @mrbigglesworth_Official 2 ปีที่แล้ว

    Nice vid. I am up to the Docker Swarm part. What IP do I use for manage IP. I have a private 10.0... confused what to use. I am using opencti in Ubuntu for personal use

  • @whotopu
    @whotopu 2 ปีที่แล้ว +1

    silly question: if i run this process on a single VM, what will be the open cti IP? AS I used manager IP once that is used as portainer ip.

  • @LJsec
    @LJsec ปีที่แล้ว

    PLease could you create a video showing how to cluster open CTI?

  • @eddiecisneros3256
    @eddiecisneros3256 5 หลายเดือนก่อน

    any instruction to deploy OPENcti on eks ?

  • @elements88xyz
    @elements88xyz ปีที่แล้ว +1

    highly appreciated . thank you for creating this.

  • @MohammedZaki-yt6hz
    @MohammedZaki-yt6hz ปีที่แล้ว

    I did the whole set-up but only on one machine, what is the command to start docker wothout using docker-swarm manager.

  • @vannkyoutub
    @vannkyoutub หลายเดือนก่อน

    Hello Taylor, i dont use docker and try to manual setup opencti on ubuntu. once i run the command " yarn serv" the terminal keep running, endless stop, i cant access terminal to run workers or connectors. good news is i can access web UI. but if i stop the above terminal or it timeout, whole platform is down. can u help me what is problem?

  • @JerleenArulandhusamy
    @JerleenArulandhusamy 2 ปีที่แล้ว

    I am not able to view the open cti UI , containers are running fine though . kindly help

  • @Invisiblewarrior078
    @Invisiblewarrior078 ปีที่แล้ว

    Everything is working properly but I got some issues when I tried to run opencti it doesn't work it shows me unhealth what is the issues

  • @mohammadhosein77
    @mohammadhosein77 2 ปีที่แล้ว

    thank you for good intro on docker swarm.

  • @virtual-riot
    @virtual-riot 2 ปีที่แล้ว

    please a question necesary i need install docker SWARN???????? Uu

  • @vimukthiperera4993
    @vimukthiperera4993 2 ปีที่แล้ว

    sir is there are any method to connect the zeek and the openCTI..

  • @juancarlosvillalbacardenas2499
    @juancarlosvillalbacardenas2499 ปีที่แล้ว

    you have opencti in OVA?

  • @filipebcs8
    @filipebcs8 ปีที่แล้ว

    What is the name of the app on the right side of your screen?

    • @Trafalgar-k6t
      @Trafalgar-k6t 5 หลายเดือนก่อน

      Have you find out yet ?

  • @amirmohamad1946
    @amirmohamad1946 7 หลายเดือนก่อน

    I have a problem. When i start to deploy the opencti stack it shows me an error that the stack had not been created and in container menu the opencti containers are stoped.
    Im running crazy.
    Plz help

    • @SudoTalon
      @SudoTalon 2 หลายเดือนก่อน

      Did you get help?

  • @helmi8962
    @helmi8962 2 ปีที่แล้ว

    What is the name of the tool that you used to access the server?

    • @ollytbh
      @ollytbh 2 ปีที่แล้ว +1

      I think it's Termius - I googled around as I also wanted to know

  • @Brando-ne2fx
    @Brando-ne2fx 2 ปีที่แล้ว

    Hello ! I'm trying to install it manually but I'm stuck with a certificate problem with rabbitmq :/ Can you make a video of the manual installation ? :)

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว

      Hey Brando,
      I will try to get around to that, probably wont be for awhile though. Any reason why you cannot go the docker route?
      Thanks for watching!

  • @testtested5825
    @testtested5825 ปีที่แล้ว

    Hey. I followed the steps however containers are not getting created looking at the services it shows "mkdir /var/lib/docker: read-only file system" error. Can someone please help me out?

  • @kumarshubham7541
    @kumarshubham7541 2 ปีที่แล้ว

    I have a single box of 16 ram and 8 core followed your process but opencti platform is not getting spinup.
    Can you please help me out

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว

      what do the logs of the elasticsearch and redis containers look like? OpenCTI requires these services to be running in a healthy state prior to the OpenCTI platform service running.

  • @banano28_oficial
    @banano28_oficial 2 ปีที่แล้ว

    At the moment I have issues with the swarm, the second vm isn't load balancing. Do you know any trick to make it works?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว

      What is it not load balancing? Are containers not getting spun up on it? Have you tried specifying the host for the image to bind too in the docker-compose file?

    • @banano28_oficial
      @banano28_oficial 2 ปีที่แล้ว

      @@taylorwalton_socfortress being honest I'm not skilled in Docker. Do you have something I can use to understand the swarming procedure? But my issue is that the second VM is not receiving the orders to share resources in portainer shows "rejected" and when a list nodes it says that the second VM is down. Also, I'm using centos 7 minimal as my os

  • @briellevenandi5128
    @briellevenandi5128 2 ปีที่แล้ว

    Trying to setup in a single server (Ubuntu 22) .. got stuck on this part ..
    when running this command: docker stack deploy --compose-file=portainer-agent-stack.yml portainer
    I got this error message: this node is not a swarm manager. Use "docker swarm init" or "docker swarm join" to connect this node to swarm and try again

    • @Vorschit
      @Vorschit ปีที่แล้ว

      any solution regarding this?

  • @openctithreatintel9088
    @openctithreatintel9088 2 ปีที่แล้ว

    Thank you for the tutorial, it greatly helped. I am having an error, where I am not able to view the open cti UI (The final step) My containers are running fine though @OpenSecure

    • @mdmehedyhasan4078
      @mdmehedyhasan4078 2 ปีที่แล้ว

      Hi, I am having the same issue. No luck at the last stage opening opencti UI. Let us know if you find any solution. TIA

    • @jonathangonzalez296
      @jonathangonzalez296 2 ปีที่แล้ว

      did you get this fixed?

  • @recon0x7f16
    @recon0x7f16 10 หลายเดือนก่อน

    I can never start up opencti given that I follow all the steps

  • @ryanwaite4283
    @ryanwaite4283 ปีที่แล้ว

    Mate, awesome video! Thanks!

  • @x0rZ15t
    @x0rZ15t 2 ปีที่แล้ว +1

    Maybe a dumb question but if you have MISP running in your environment, what is the reason to deploy OpenCTI?

    • @ollytbh
      @ollytbh 2 ปีที่แล้ว +1

      Different native feeds and different options for correlation / enrichment / export etc. We have an organisation that only supports MISP output, so we take that then feed it into OpenCTI.

  • @petarsimovic5628
    @petarsimovic5628 2 ปีที่แล้ว

    Thanks. This gives me some ideas.

  • @UnsettlingSun
    @UnsettlingSun 2 ปีที่แล้ว

    Thanks for the awesome tutorial! Managed to set this up once. Im trying to set it up again with a domain and https. Any suggestions on the best way to go about it? Would I just have to run letsencrypt on the manager node or would I have to do changes on the docker compose file?

    • @taylorwalton_socfortress
      @taylorwalton_socfortress  2 ปีที่แล้ว

      Glad you got some value out of it :). I would recommend using a reverse proxy such as Nginx or Apache to sit in front of your Opencti Plaform stack. Then you can use letsencrypt to generate a free cert and provide some security around the web app. There are a ton of posts out on the internet detailing setting up a simple reverse proxy that could hopefully be helpful.
      Thanks for watching :)

  • @charlie9585
    @charlie9585 ปีที่แล้ว

    What an awesome video!

  • @mahbubalam1533
    @mahbubalam1533 ปีที่แล้ว

    Wonderful Tutorial.

  • @RomeoPL
    @RomeoPL 10 หลายเดือนก่อน

    very helpful, thanks ;)

  • @joelmejia6702
    @joelmejia6702 ปีที่แล้ว

    Docker info:
    Swarm: error
    Error: rpc error: code: deadlineExceeded desc= contexto deadline exceeded
    Warning: No swap limit support.
    When I want do docker Swarm join - - token........
    Show: this node is already parte of a Swarm. Use docker Swarm leave

    • @joelmejia6702
      @joelmejia6702 ปีที่แล้ว

      Then node left the Swarm, And execute docker again And show error again:
      This node is already parte of a Swarm.....
      Please helpme

  • @SuperHumanJeremiah
    @SuperHumanJeremiah 15 วันที่ผ่านมา

    notion guide no longer exists
    🙃

  • @itclam
    @itclam 2 ปีที่แล้ว

    great. thanks !

  • @mrait
    @mrait 7 หลายเดือนก่อน

    nice

  • @recon0x7f16
    @recon0x7f16 10 หลายเดือนก่อน

    I literally can spin up misp in like 5 minutes

  • @francisb8825
    @francisb8825 2 ปีที่แล้ว

    Great! thank you