-
Notifications
You must be signed in to change notification settings - Fork 640
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
MISP Sharing Improvements #366
Comments
Added suggestions from #433 |
Commit 4ec4f0e uses new API of MISP to identify which event can be updated |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Request Type
Feature Request
Work Environment
Problem Description
The current implementation of MISP sharing in TheHive can be improved in several ways.
Create an Extended Event When not Able to Export
When an analyst attempts to update a MISP event on which the account used by TheHive to connect to the MISP instance is not part of the original creator organization, the current implementation in TheHive will display a
you do not have permission to do that
error produced by MISP. In this case, TheHive should offer the analyst the ability to create an extended event (http://www.misp-project.org/2018/04/19/Extended-Events-Feature.html).Add Sightings and IDS Flags During Export
Once #365 is implemented, TheHive should mark
sightings
and activate theIDS
flag on each attribute exported to MISP corresponding to an observable that is marked asIOC
andsighted
in TheHive.Provide Context
When sharing a case to a MISP instance, provide context such as TheHive's name instance, link to the case, and other metadata.
The text was updated successfully, but these errors were encountered: