BEERUMP 17 / 2017-06-22
TLP:WHITE
Saâd Kadhi TheHive Project
HOW AN IOC CAN LEAD TO ANOTHER? Sad Kadhi TheHive Project Automate - - PowerPoint PPT Presentation
BEERUMP 17 / 2017-06-22 TLP:WHITE HOW AN IOC CAN LEAD TO ANOTHER? Sad Kadhi TheHive Project Automate bulk observable analysis through a REST API Can be queried Web UI Analyzers can be developed in any programming language that
BEERUMP 17 / 2017-06-22
TLP:WHITE
Saâd Kadhi TheHive Project
language that is supported by Linux
useful for Red Teams too
ARCHITECTURE
BACKEND STORAGE FRONTEND REST APIS
HTTP
A A A A ANALYZERS REST APIS
HTTP
CORTEX
23 ANALYZERS (AND MORE ARE COMING) FORTIGUARD URL CATEGORY CIRCL PDNS CIRCL PSSL MISP SEARCH DOMAINTOOLS PASSIVETOTAL VIRUSTOTAL ABUSE FINDER FILEINFO OUTLOOK MSG PARSER NESSUS OTXQUERY HIPPOCAMPE GOOGLE SAFE BROWSING DNSDB YARA PHISHING INITIATIVE PHISHTANK MAXMIND JOE SANDBOX SPLUNK SEARCH FIREHOL VMRAY IRMA MCAFEE ATD CUCKOO FAME INTELMQ WHOISXMLAPI FIREEYE AX HYBRID ANALYSIS
Analyzers Expansion Modules E x p
t c a s e s Enrich events Additional analyzers Analyze observables Search observables within MISP events Alert Sources (SIEM, email, …) Raise alerts Alert Feeders P
l e v e n t s
LET’S GET TO WORK
visiting the Polish Supervision Authority (www[.]knf[.]gov[.]pl) -> Watering hole attack -> Custom EK with exploits stolen from Neutrino & RIG
carry the same attack: Comisión Nacional Bancaria y de Valores (MX), Banco República (UY)
information-stolen-by-unknown-attackers/
HOW CAN AN IOC LEAD TO ANOTHER?
maybe?)
knf[.]gov[.]pl MISP Search 1 event knf[.]gov[.]pl VirusTotal
hxxp://knf.gov.pl/DefaultDesign/Layouts/ KNF2013/resources/accordian-src.js? ver=11
d4616f9706403a0d5a2f9a872 6230a4693e4c95c58df5c753c cc684f1d3542e2 VirusTotal 47/61 sap[.]misapor[.]ch MISP Search Galaxy Lazarus Group, Target Finance
GET THE SOFTWARE
package or built from the source code
and a decent computer