TheHive-Project / TheHive-Project/Cortex-Analyzers

[Bug] ERROR SENDIND DATA TO MISP WITH CORTEX ANALYZER AND THEHIVE

Open
#1,316 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
490
Forks
405
Avg merge
2d 43m
Merged PRs (30d)
8

Description

Describe the bug
I got an error sometimes with MISP analyzer with the new version of it v2.5.5 and I can't send cases to MISP with Thehive

To Reproduce
Steps to reproduce the behavior:

  1. enable MISP analyzer and have an instance with MISP v2.5.5
  2. analize one IOC (IP, URL, etc)
  3. get the result of analysis

Expected behavior
I expect a good result of trying to view if exist events in MISP instance, not sometimes works properly and sometimes not

Work environment

  • Client OS: Linux RHEL 8.10
  • Browse type and version: Google Chrome
  • Cortex version: 3.1
  • Thehive 4
  • Cortex Analyzer/Responder name: MISP
  • Cortex Analyzer/Responder version: 2.1

Additional context

HI everyone I have a problem trying to integrate thehive and cortex with MISP in the new version of MISP v2.5.5

I have Thehive 4 and Cortex 3.1

When I integrated Cortex with MISP and try to analyze one IP sometimes I got an error and sometimes works properly

Image

Image

Image

with thehive I can't send or import a case to MISP I got the following error

Image

Image

Im using a self sign certificate with MISP but Im using the code to use the certificate in thehive

Image

I tried installing the version 2.5.4 of pymisp but I got errors when I installing it or something went wrong

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the intermittent MISP analyzer failure with MISP 2.5.5, Cortex 3.1, TheHive 4, and the self-signed certificate setup described in the issue. Inspect the MISP analyzer integration and the errors shown in the attached screenshots, including the attempted pymisp 2.5.4 installation. Done means analysis and TheHive case import or sending work consistently.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.