Lecture 4 pt. 7 Flashcards
What does MISP stand for?
MISP stands for Malware Information Sharing Platform.
What is TheHive?
TheHive is a scalable, open source, and free Security Incident Response Platform, integrated with MISP, designed for SOCs, CSIRTs, CERTs, and information security practitioners.
What is a Detection Playbook?
A Detection Playbook consists of individual Plays that describe different aspects of a particular detection strategy.
Fill in the blank: TheHive is a scalable, open source Security Incident Response Platform tightly integrated with _______.
MISP
What is the primary focus of osquery?
To leverage a relational data-model to describe a device using SQL commands
What is Wazuh?
A full-featured HIDS solution providing endpoint protection mechanisms
What does Snort do?
It’s a Network Intrusion Detection System (NIDS) that sniffs network traffic and generates alerts
What is the function of the Cyber Swiss Army Knife, CyberChef?
To carry out various ‘cyber’ operations within a web browser
What tool provides an interactive dashboard for visualizing NSM data?
Kibana
What are the four priority levels in Sguil alerts?
- Very low
- Low
- Medium
- High