Last modified: Sun Feb 28 2021 09:22:59 GMT+0100 (Central European Standard Time)
code block or value
- Used for variable, function or menu names in MISP.
The language in this book is American English. All the screenshots and examples are in English.
The same code of conduct applies to this book as for the main MISP project.
As a book can some times be considered the inadvertent soul of a piece of software, please take good care and consideration of our
Code of Conduct. The CoC can be read here.
The examples and screenshots provided in this book have been created with the MISP Autogenerated VM.
To get a copy of the latest VM click here
In general when talking about a network of inter-connected MISP servers, each server is a MISP instance. Whilst we have no strong feelings towards anyones naming schemes, as a rule of thumb try to have a scheme that makes everyday use easy when analysts need to talk about remote MISP instances.
The hostname used for the instance in this book is
misp.local and we will henceforth refer to it either by name or as
local MISP instance.
As MISP is a platform to support information sharing, example organisations are often used within this book.
A set of users and organisations are used in the different examples.
The following two organisations are regularly used as example:
- Setec Astronomy with UUID
- Acme Finance with UUID
Starting from MISP 2.4.71, the example organisations with the above mentioned UUID are blocklisted to avoid
large distribution of sample events while testing a MISP instance. If you want to test your distribution, the
sample organisation blocklisting can be removed in
Manage Org blocklists.
As with the example organisations, we want to make this book as useful as possible by using real life examples.
The following IOC examples have been used: