The Wayback Machine - https://web.archive.org/web/20200309084648/https://github.com/topics/incident-response
Skip to content
#

incident-response

Here are 190 public repositories matching this topic...

jonstewart
jonstewart commented Feb 13, 2020

PRs to this repository are checked with a variety of tools. Having looked through this repository and the Developer's Guide (http://wiki.sleuthkit.org/index.php?title=Developer%27s_Guide), I can find no documentation about these tools and how to accommodate the associated tests on PRs. As such, several contributed PRs quite understandably fail these tests. Please add documentation to assist and en

TheHive
crackytsi
crackytsi commented Mar 3, 2020

Bug / Feature Request

Work Environment

Question Answer
OS version (server) Debian
OS version (client) 10
TheHive version / git hash 4 RC1
Package Type DEB

Problem Description

There are no longer any default dashboards

Possible Solutions

Add the default da

theckman
theckman commented Apr 25, 2019

One change we are seeing in our industry is the wider adoption of the belief that being able to distill an incident down to a single root cause is a myth[1][2]. As the complexities of our systems grow the complexities of our incidents grow, and trying to isolate an incident to one item doesn't result in the types of learnings we need to come out of those incidents.

The truth is that each incide

capnspacehook
capnspacehook commented Jan 15, 2019

Unit tests need to be created that tests obfuscating with all possible Mutator permutations that are 2 Mutators long. So basically given the dozen or so current Mutators, make sure Mutators don't just work on their separately, but together as well. I've run into a few random cases where using Mutators in specific combinations produces faulty payloads, and want a test that can do this for me.

Us

Cortex
ZSZ72
ZSZ72 commented Dec 3, 2019

Work Environment

Question Answer
OS version (server) Ubuntu
OS version (client) 10
Cortex version / git hash Fresh install from DEB
Package Type DEB
Browser type & version Firefox

Problem Description

After updating database in Cortex, when the create adminis

velociraptor
scudette
scudette commented Feb 29, 2020

Artifact output is one or more tables with column names set by the VQL itself. It is often convenient to forward artifact output to additional systems and so it would be nice to develop some naming guidelines around columns.

Additionally it would be useful to develop a minimal set of columns to output so each row can be tagged in an external system (e.g. Elastic index).

This bug is to facili

pichlou
pichlou commented Jan 7, 2019

Hi
i am using docker-compose in windows 7
postgres,rabbitmq and django application services build,but nginx service has an error!

nginx:
volumes:
- ./nginx_docker.conf:/etc/nginx/conf.d/default.conf

in this part "nginx_docker.conf" is not a directory and i have error "not a directory" in running "docker-compose up" command.
what is your solution for my problem?

TheHiveDocs
cloudtracer
cloudtracer commented Jan 1, 2017

Need configurations for locally sourced CMDB IP / FQDN lookups. I don't have access to these systems so I need some community help for them!

Current List:

  • ServiceNow
  • AlienVault OCS
  • SolarWinds

How can you help?

  • Contribute to this list of nice to haves.
  • Create a lookup request configuration to any of the items on this list (Check out the MISP configuration for best practic
Cortex-Analyzers
milesflo
milesflo commented Feb 12, 2020

Describe the bug
The following analyzers are missing cortexutils:

  • SpamhausDBL
  • ProofPoint
  • TeamCymruMHR
  • Umbrella

To Reproduce
find ./analyzers -name "requirements.txt" -print -exec cat {} \;

Complementary information
The current dep. installation implementation allowed this error to slip under the radar, but containerized analyzers did not have this critical depe

bug

Improve this page

Add a description, image, and links to the incident-response topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the incident-response topic, visit your repo's landing page and select "manage topics."

Learn more

You can’t perform that action at this time.