Use cases
Wazuh and TheHive integration offers a lot of benefits to SOC analysts and incident response teams. We will go through different use cases to explore several features of TheHive and MISP that work extremely well with Wazuh. We will go through some common use cases such as investigating suspicious file and network connections and tracking TTPs. In this section, we will cover the following topics:
- Pre-requisites
- Reviewing alerts
- Creating a case
- Analyzing file observable
- Analyzing network observable
- Managing TTPs
Pre-requisites
Before we get into some use cases of threat intelligence and analysis with Wazuh, TheHive, and MISP, we need to ensure these requirements are fulfilled:
- A Wazuh server
- An Ubuntu server running TheHive and Cortex using Docker
- An Ubuntu server running an MISP server
- Ubuntu Desktop or Ubuntu Server with the Wazuh agent installed
Reviewing alert
Once you integrate Wazuh with TheHive, you...