All Projects → TheHive-Project → Docker-Templates

TheHive-Project / Docker-Templates

Licence: AGPL-3.0 license
Docker configurations for TheHive, Cortex and 3rd party tools

Programming Languages

shell
77523 projects

Projects that are alternatives of or similar to Docker-Templates

Thehive
TheHive: a Scalable, Open Source and Free Security Incident Response Platform
Stars: ✭ 2,300 (+3139.44%)
Mutual labels:  incident-response, dfir, thehive, cortex
Packrat
Live system forensic collector
Stars: ✭ 16 (-77.46%)
Mutual labels:  incident-response, dfir
CCXDigger
The CyberCX Digger project is designed to help Australian organisations determine if they have been impacted by certain high profile cyber security incidents. Digger provides threat hunting functionality packaged in a simple-to-use tool, allowing users to detect certain attacker activities; all for free.
Stars: ✭ 45 (-36.62%)
Mutual labels:  incident-response, dfir
RdpCacheStitcher
RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
Stars: ✭ 176 (+147.89%)
Mutual labels:  incident-response, dfir
Vast
🔮 Visibility Across Space and Time
Stars: ✭ 227 (+219.72%)
Mutual labels:  incident-response, dfir
Dfirtrack
DFIRTrack - The Incident Response Tracking Application
Stars: ✭ 232 (+226.76%)
Mutual labels:  incident-response, dfir
TheHiveHooks
This is a python tool aiming to make using TheHive webhooks easier.
Stars: ✭ 22 (-69.01%)
Mutual labels:  dfir, thehive
Pypowershellxray
Python script to decode common encoded PowerShell scripts
Stars: ✭ 192 (+170.42%)
Mutual labels:  incident-response, dfir
MEAT
This toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices
Stars: ✭ 101 (+42.25%)
Mutual labels:  incident-response, dfir
uac
UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
Stars: ✭ 260 (+266.2%)
Mutual labels:  incident-response, dfir
S1EM
This project is a SIEM with SIRP and Threat Intel, all in one.
Stars: ✭ 270 (+280.28%)
Mutual labels:  thehive, cortex
Atc React
A knowledge base of actionable Incident Response techniques
Stars: ✭ 226 (+218.31%)
Mutual labels:  incident-response, dfir
Dfir Orc
Forensics artefact collection tool for systems running Microsoft Windows
Stars: ✭ 202 (+184.51%)
Mutual labels:  incident-response, dfir
Cortex Analyzers
Cortex Analyzers Repository
Stars: ✭ 246 (+246.48%)
Mutual labels:  incident-response, dfir
Pockint
A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️
Stars: ✭ 196 (+176.06%)
Mutual labels:  incident-response, dfir
pyarascanner
A simple many-rules to many-files YARA scanner for incident response or malware zoos.
Stars: ✭ 23 (-67.61%)
Mutual labels:  incident-response, dfir
MindMaps
#ThreatHunting #DFIR #Malware #Detection Mind Maps
Stars: ✭ 224 (+215.49%)
Mutual labels:  incident-response, dfir
Imago Forensics
Imago is a python tool that extract digital evidences from images.
Stars: ✭ 175 (+146.48%)
Mutual labels:  incident-response, dfir
ThePhish
ThePhish: an automated phishing email analysis tool
Stars: ✭ 676 (+852.11%)
Mutual labels:  incident-response, thehive
INDXRipper
Carve file metadata from NTFS index ($I30) attributes
Stars: ✭ 32 (-54.93%)
Mutual labels:  incident-response, dfir

Welcome to TheHive Project's Docker Templates repository.

It's hosting docker configurations for TheHive, Cortex and 3rd party tools integrations.

What's in it?

This repository aims to be a location where TheHive and Cortex users can find and share docker compose configuration files for

  • TheHive
  • Cortex
  • MISP
  • Reverse Proxies
  • OAuth Providers
  • Workflow and automation tools
  • Feeders

Configuration

For the sake of simplicity, the provided docker-compose templates are made simple, without providing the full configuration options of each docker image.

We provide a documentation page for main image used by the templates. For the full docker image options, you need to rely on the image's official documentation.

Available templates

Basic templates

Custom templates

TheHive Only

Thehive + Cortex

Orchestration

TODO

The list bellow includes the docker-compose configurations to be done:

  • TheHive 3 + Elasticsearch
  • TheHive 4 + BerkleyDB
  • TheHive 4 + Cassandra
  • Cortex 3 + dockerized neurons
  • Cortex 3 + local neurons
  • Add reverse proxy
    • Caddy?
    • Nginx
    • Traefik
  • Add oauth providers
    • keycloak ?
    • Fusionauth ?

Contributing

Please see our Code of conduct. We welcome your contributions. Please feel free to fork the code, play with it, make some patches and send us pull requests via issues.

Contributors

All Contributors

Thanks goes to these wonderful people (emoji key):


Nabil Adouani

💻 📖 👀 ⚠️

garanews

💻 📖

aacgood

💻 📖

Miles Florence

💻

julien jamet

📖

Jonas Plum

📖

Robert Haist

💻

Daniel Federschmidt

💻

Keijo Korte

💻

This project follows the all-contributors specification. Contributions of any kind welcome!

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].