MISP training

MISP is the de facto standard for sharing cyber threat intelligence, from IOCs to strategic information. In one day, your analysts learn to store, correlate and share threat intel in MISP, so standalone incidents become an organisational body of knowledge.

Audience
CERT, CSIRT and SOC teams
Format
Public or in-company
Duration
1 day
Language
Dutch or English

Who it is for

MISP is widely used by CERT, CSIRT and SOC teams. This training is for members of those teams who want to learn how to work with MISP.

It is a user training: it covers using the platform, not installing or administering it.

What you will be able to do

  • Understand MISP’s data model
  • Retrieve your information in smart ways
  • Share your intelligence with other organisations
  • Create rich events that feed your SIEM, IDS or IPS
  • Correlate incidents with historical and ongoing events
  • Generate timelines and event graphs for human consumption
  • Aggregate events for statistical purposes

In short: use cases that are useful at technical, tactical and strategic level.

Practical

The training includes course materials and access to the lab environment. Course materials are in English; the training itself is given in Dutch or English.

Bring a laptop. Ideally, bring one or more of your organisation’s own incidents to model during the day. If that is not possible, we provide examples.

Book the MISP training

Ask us about upcoming dates or an in-company session for your team.

Email us