MISP training
MISP is the de facto standard for sharing cyber threat intelligence, from IOCs to strategic information. In one day, your analysts learn to store, correlate and share threat intel in MISP, so standalone incidents become an organisational body of knowledge.
- Audience
- CERT, CSIRT and SOC teams
- Format
- Public or in-company
- Duration
- 1 day
- Language
- Dutch or English
Who it is for
MISP is widely used by CERT, CSIRT and SOC teams. This training is for members of those teams who want to learn how to work with MISP.
It is a user training: it covers using the platform, not installing or administering it.
What you will be able to do
- Understand MISP’s data model
- Retrieve your information in smart ways
- Share your intelligence with other organisations
- Create rich events that feed your SIEM, IDS or IPS
- Correlate incidents with historical and ongoing events
- Generate timelines and event graphs for human consumption
- Aggregate events for statistical purposes
In short: use cases that are useful at technical, tactical and strategic level.
Practical
The training includes course materials and access to the lab environment. Course materials are in English; the training itself is given in Dutch or English.
Bring a laptop. Ideally, bring one or more of your organisation’s own incidents to model during the day. If that is not possible, we provide examples.