Lecture 4 pt. 7 Flashcards

1
Q

What does MISP stand for?

A

MISP stands for Malware Information Sharing Platform.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is TheHive?

A

TheHive is a scalable, open source, and free Security Incident Response Platform, integrated with MISP, designed for SOCs, CSIRTs, CERTs, and information security practitioners.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a Detection Playbook?

A

A Detection Playbook consists of individual Plays that describe different aspects of a particular detection strategy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Fill in the blank: TheHive is a scalable, open source Security Incident Response Platform tightly integrated with _______.

A

MISP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the primary focus of osquery?

A

To leverage a relational data-model to describe a device using SQL commands

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Wazuh?

A

A full-featured HIDS solution providing endpoint protection mechanisms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does Snort do?

A

It’s a Network Intrusion Detection System (NIDS) that sniffs network traffic and generates alerts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the function of the Cyber Swiss Army Knife, CyberChef?

A

To carry out various ‘cyber’ operations within a web browser

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What tool provides an interactive dashboard for visualizing NSM data?

A

Kibana

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the four priority levels in Sguil alerts?

A
  • Very low
  • Low
  • Medium
  • High
How well did you know this?
1
Not at all
2
3
4
5
Perfectly