TheHive-Project / TheHive-Project/Cortex-Analyzers
[Bug] ERROR SENDIND DATA TO MISP WITH CORTEX ANALYZER AND THEHIVE
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 490
- Forks
- 405
- Avg merge
- 2d 43m
- Merged PRs (30d)
- 8
Description
Describe the bug
I got an error sometimes with MISP analyzer with the new version of it v2.5.5 and I can't send cases to MISP with Thehive
To Reproduce
Steps to reproduce the behavior:
- enable MISP analyzer and have an instance with MISP v2.5.5
- analize one IOC (IP, URL, etc)
- get the result of analysis
Expected behavior
I expect a good result of trying to view if exist events in MISP instance, not sometimes works properly and sometimes not
Work environment
- Client OS: Linux RHEL 8.10
- Browse type and version: Google Chrome
- Cortex version: 3.1
- Thehive 4
- Cortex Analyzer/Responder name: MISP
- Cortex Analyzer/Responder version: 2.1
Additional context
HI everyone I have a problem trying to integrate thehive and cortex with MISP in the new version of MISP v2.5.5
I have Thehive 4 and Cortex 3.1
When I integrated Cortex with MISP and try to analyze one IP sometimes I got an error and sometimes works properly
with thehive I can't send or import a case to MISP I got the following error
Im using a self sign certificate with MISP but Im using the code to use the certificate in thehive
I tried installing the version 2.5.4 of pymisp but I got errors when I installing it or something went wrong
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the intermittent MISP analyzer failure with MISP 2.5.5, Cortex 3.1, TheHive 4, and the self-signed certificate setup described in the issue. Inspect the MISP analyzer integration and the errors shown in the attached screenshots, including the attempted pymisp 2.5.4 installation. Done means analysis and TheHive case import or sending work consistently.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100