Using the provided MISP VM ova file, import it on VirtualBox and respond to the questions below. Also, add a screenshot of every step. NOTE : you might want to add an Internal interface and assign an...

1 answer below »

Using the provided MISP
VM ova file, import it on VirtualBox and respond to the questions
below. Also, add a screenshot of every step.











NOTE: you might
want to add an Internal interface and assign an IP address (edit the
file
/etc/network/interfaces), so
that you can connect to the WebApp from a browser.

















  1. Why there are no events when clicking on Home?































  1. Go to Sync Actions → List Feeds to check the list of default

    feeds.































  1. Load all default feed metadata and check how it looks like.































  1. In Home there is still no events. What do you have to do to see, for

    instance, IPs blocked by Snort? Explain step by step.































  1. Prove that these events are available in Home.































  1. Click on the ID to populate information about this event. What kind

    of information is shown at the list at the bottom? What this

    information represents?































  1. Using ipgeolocation.io, locate one of the entries in the list.

    Choose it randomly.









  2. Go back to the list of feeds and add all related to malware (use the

    search engine). If it takes a while, check in Administration →

    Jobs the background tasks. Once done, prove again you got events

    from all of them.























  1. Show the details of URLhaus.































  1. In the Galaxies menu, you can search for topics. Show the

    information regarding malware stealer.































  1. What feed would you use for phishing URLs?































  1. And for spam?














Using the provided MISP VM ova file, import it on VirtualBox and respond to the questions below. Also, add a screenshot of every step. NOTE: you might want to add an Internal interface and assign an IP address (edit the file /etc/network/interfaces), so that you can connect to the WebApp from a browser. 1. Why there are no events when clicking on Home? 2. Go to Sync Actions → List Feeds to check the list of default feeds. 3. Load all default feed metadata and check how it looks like. 4. In Home there is still no events. What do you have to do to see, for instance, IPs blocked by Snort? Explain step by step. 5. Prove that these events are available in Home. 6. Click on the ID to populate information about this event. What kind of information is shown at the list at the bottom? What this information represents? 7. Using ipgeolocation.io, locate one of the entries in the list. Choose it randomly. 8. Go back to the list of feeds and add all related to malware (use the search engine). If it takes a while, check in Administration → Jobs the background tasks. Once done, prove again you got events from all of them. 9. Show the details of URLhaus. 10. In the Galaxies menu, you can search for topics. Show the information regarding malware stealer. 11. What feed would you use for phishing URLs? 12. And for spam?
Answered 1 days AfterSep 11, 2022

Answer To: Using the provided MISP VM ova file, import it on VirtualBox and respond to the questions below....

Naveen Kumar answered on Sep 12 2022
59 Votes
Using the provided MISP VM ova file, import it on VirtualBox and respond to the questions below. Also, add a screenshot of every step.
NOTE: you might want to add an Internal interface and assign an IP address (edit the file /etc/network/interfaces), so that you can connect to the WebApp from a browser.
Network settings with NATip and local ip
Local ip: 192.168.253.135/24
NAT IP: 202.173.124.142
1. Why there are no events when clicking on Home?
By default there would be no events, due to no event id or event config has been selected.
We have select the even id from list of events,
Based in the priority, the event would be high or medium or low.
Config:
Selected the data: 09/12/2022
Distribution: Select All communities, if you have any selected community then go with it, they are four other communities option are available.
Threat level: High or Medium or Low. I have chosen high for assignment.
Analysis: You can select, at what stage the analysis should start.
Event info: Information about event.
Extended event: optional.
2. Go to Sync Actions → List Feeds to check the list of default feeds.
Feed has not enabled by default, we have to enable by select appropriate options.
In this below example, I have enabled ID 1 for assignment reason.
As you can see 2 ID was not enabled.
2 ID is enabled and...
SOLUTION.PDF

Answer To This Question Is Available To Download

Related Questions & Answers

More Questions »

Submit New Assignment

Copy and Paste Your Assignment Here