Skip to content

Commit

Permalink
Update thehive.md
Browse files Browse the repository at this point in the history
  • Loading branch information
Men-hau authored Nov 2, 2023
1 parent 29fec0e commit 73e905f
Showing 1 changed file with 33 additions and 16 deletions.
49 changes: 33 additions & 16 deletions _shared_content/intelligence_center/integrations/thehive.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ Collect Sekoia.io CTI feed in an existing Cortex instance self-managed, for any
### 1. Setup the Analyzer configuration

1. Select your _Organization_ on the top right corner
![Orga_setup_1](/assets/intelligence_center/orga_setup_1.png){: style="width: 70%; max-width: 70%"}
![Orga_setup_1](/assets/intelligence_center/orga_setup_1.png){: style="width: 60%; max-width: 60%"}

2. Go to _Analyzers Config_ tab and Search `SekoiaIntelligenceCenter`
![Orga_setup_2](/assets/intelligence_center/orga_setup_2.png){: style="width: 60%; max-width: 60%"}
Expand Down Expand Up @@ -56,9 +56,9 @@ Here is below one example of setup to be done for the 3 analyzers:

## 3. Sekoia intelligence in TheHive Cortex

Matching of Sekoia intelligence
In the following section, you will find information on how Sekoia intelligence is available in TheHive Cortex

### Here is a summary of the information
### Summary of the information

|Analyzers|Cortex|Sekoia.io|
|--|--|--|
Expand All @@ -68,17 +68,33 @@ Matching of Sekoia intelligence

### Sekoia Intelligence information on Sekoia.io that is available on Cortex

- SEKOIAIntelligenceCenter_Indicators_1_0
#### SEKOIAIntelligenceCenter_Indicators_1_0

1. Search indicator in Sekoia
![TheHive_Sekoia_connector1](/assets/intelligence_center/searchCTI_Sekoia_objects.png){: style="width: 50%; max-width: 50%"}

2. Sekoia.io Indicator information available on Cortex
![TheHive_Sekoia_connector1](/assets/intelligence_center/searchCTI_Sekoia_objects_2.png){: style="width: 100%; max-width: 100%"}

- SEKOIAIntelligenceCenter_Context_1_0
------

#### SEKOIAIntelligenceCenter_Context_1_0

1. Search observable in Sekoia
![TheHive_Sekoia_connector1](/assets/intelligence_center/searchCTI_Sekoia_context_1.png){: style="width: 100%; max-width: 100%"}

2. Sekoia.io observable information available on Cortex
![TheHive_Sekoia_connector1](/assets/intelligence_center/searchCTI_Sekoia_context_2.png){: style="width: 100%; max-width: 100%"}
![TheHive_Sekoia_connector1](/assets/intelligence_center/searchCTI_Sekoia_context_3.png){: style="width: 100%; max-width: 100%"}

- SEKOIAIntelligenceCenter_Observables_1_0

------

#### SEKOIAIntelligenceCenter_Observables_1_0

1. Search observable in Sekoia
![TheHive_Sekoia_connector1](/assets/intelligence_center/searchCTI_Sekoia_observables.png){: style="width: 30%; max-width: 30%"}

2. Sekoia.io observable information available on Cortex
![TheHive_Sekoia_connector1](/assets/intelligence_center/searchCTI_Sekoia_observables_2.png){: style="width: 100%; max-width: 100%"}

## 4. Steps to retrieve and search Sekoia intelligence
Expand All @@ -91,7 +107,7 @@ Matching of Sekoia intelligence

#### Indicators

1. Go to Sekoia connector _Analyzers > SEKOIAIntelligenceCenter_ and click on button Run
1. Go to Sekoia.io connector _Analyzers > SEKOIAIntelligenceCenter_ and click on button Run
![TheHive_Sekoia_connector1](/assets/intelligence_center/search_SekoiaCTI-1_indicators.png){: style="width: 80%; max-width: 80%"}

2. Fill the information
Expand All @@ -100,16 +116,17 @@ Matching of Sekoia intelligence
3. Check the indicator in Jobs History
![TheHive_Sekoia_job](/assets/intelligence_center/search_SekoiaCTI-3_indicators.png){: style="width: 60%; max-width: 60%"}

4. Check the Sekoia indicator
4. Check the Sekoia.io indicator
![TheHive_Sekoia_feed1](/assets/intelligence_center/search_SekoiaCTI-4_indicators.png){: style="width: 100%; max-width: 100%"}

5. In Sekoia.io
5. Indicator in Sekoia.io Intelligence page
![TheHive_Sekoia_objects](/assets/intelligence_center/searchCTI_Sekoia_objects.png){: style="width: 40%; max-width: 40%"}

------

#### Context

1. Go to Sekoia connector _Analyzers > SEKOIAIntelligenceCenter_ and click on button Run
1. Go to Sekoia.io connector _Analyzers > SEKOIAIntelligenceCenter_ and click on button Run
![TheHive_Sekoia_connector1](/assets/intelligence_center/search_SekoiaCTI-1_context.png){: style="width: 80%; max-width: 80%"}

2. Fill the information
Expand All @@ -118,17 +135,17 @@ Matching of Sekoia intelligence
3. Check the observable in Jobs History
![TheHive_Sekoia_job](/assets/intelligence_center/search_SekoiaCTI-3_context.png){: style="width: 60%; max-width: 60%"}

4. Check the Sekoia observable
4. Check the Sekoia.io observable
![TheHive_Sekoia_feed1](/assets/intelligence_center/search_SekoiaCTI-4_context.png){: style="width: 100%; max-width: 100%"}

5. In Sekoia.io
5. Observable in Sekoia.io Intelligence page
![TheHive_Sekoia_Observable](/assets/intelligence_center/searchCTI_Sekoia_observables.png){: style="width: 40%; max-width: 40%"}

------

#### Observables

1. Go to Sekoia connector _Analyzers > SEKOIAIntelligenceCenter_ (any) and click on button Run
1. Go to Sekoia.io connector _Analyzers > SEKOIAIntelligenceCenter_ (any) and click on button Run
![TheHive_Sekoia_connector1](/assets/intelligence_center/search_SekoiaCTI-1_observables.png){: style="width: 80%; max-width: 80%"}

2. Fill the information
Expand All @@ -137,10 +154,10 @@ Matching of Sekoia intelligence
3. Check the observable in Jobs History
![TheHive_Sekoia_job](/assets/intelligence_center/search_SekoiaCTI-3_observables.png){: style="width: 60%; max-width: 60%"}

4. Check the Sekoia observable
4. Check the Sekoia.io observable
![TheHive_Sekoia_feed1](/assets/intelligence_center/search_SekoiaCTI-4_observables.png){: style="width: 100%; max-width: 100%"}

5. In Sekoia.io
5. Observable in Sekoia.io Intelligence page
![TheHive_Sekoia_Observable](/assets/intelligence_center/searchCTI_Sekoia_observables.png){: style="width: 40%; max-width: 40%"}

## 5. Troubleshoot
Expand Down

0 comments on commit 73e905f

Please sign in to comment.