Incident response guide - V1D1AN/S1EM Wiki

Original URL: https://github.com/V1D1AN/S1EM/wiki/Incident-response-guide

Incident response

TheHive / Cortex

With S1EM, you have tools like TheHive and Cortex for the incident response.

When your alert arrives in TheHive:

Alert_send_to_thehive

You can click on Preview import for see the alert:

Alert_thehive

Click on Import

TheHive

Your case is create and click on Observables:

TheHive2

Select all observables ( 1 ), click on Selected observables ( 2 ), click on Run analyzers ( 3 ):

TheHive3

Select the analyzers that you want and click on Run selected analyzers:

TheHive4

TheHive send to cortex the observables for analyse:

TheHive5

Fleet

Todo

CyberChef

Cyberchef is a html page with several tools for help the analyzer like conversion tools:

Cyberchef