MISP Training Administration and Deployment of MISP software

แชร์
ฝัง
  • เผยแพร่เมื่อ 2 ม.ค. 2025

ความคิดเห็น • 7

  • @mllenessmarie
    @mllenessmarie ปีที่แล้ว +1

    Very good overview for admins, thank you for sharing this recording!

  • @draass227
    @draass227 ปีที่แล้ว

    Great session, however, I've success to deploy MISP made it up and running, then integrtae the HTTPS with our custom cert.
    I cannot find a cookbook to integrate MISP with the LDAP/AD at all, tried with multiple ways based on information I found in Github and number of forums, no luck.
    Please advice. Thank you.

  • @yousufturkey9273
    @yousufturkey9273 9 หลายเดือนก่อน

    It's a nice video. I have a question. why would one want to use so many organizations? normally users work in one organization. are you explaining this from a services perspective where you are managing multiple organizations?

  • @praveenpatil6687
    @praveenpatil6687 ปีที่แล้ว

    Dear, could you please help me with the below questions, thank you
    1.Once we deploy MISP as a stand-alone, Where to link MISP to monitor alerts? SIEM/SOAR or EDR , LDAP , AWS or any other? (In other words: If I deploy MISP in server, how does it look for threats in our environment, what logs does it to need to check, what should I link MISP to AWS? LDAP? Any other? To check all the machines)
    2.Do MISP gather information from various OSINT tools and compare the risk/threat in our environment ?

    • @yousufturkey9273
      @yousufturkey9273 9 หลายเดือนก่อน

      as of i know MISP works against the information you put in and matches with the feeds it has, the information you get will be other sources such as Zeek, Suricata, Wazuh and many others. maybe there is an automated way which I am not aware of.

  • @SomnathDas-uw4bg
    @SomnathDas-uw4bg 9 หลายเดือนก่อน

    can you please make a video regarding the integration of MISP with Splunk??

  • @johnchong9660
    @johnchong9660 ปีที่แล้ว

    how to update the latest feeds ?