Skip to main content
Back to all walkthroughs
Room Icon

MISP

Max room.

Walkthrough on the use of MISP as a threat sharing platform.

medium

60 min

65,438

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

This room explores the (Malware & Threat Sharing Platform) through its core objective to foster the sharing of structured threat information among security analysts, malware researchers, and IT professionals. In this room, you will pivot from a single hash into a full campaign picture using a pre-populated MISP instance, and learn how to integrate MISP into your processes.

Learning Objectives

  • Learn the purpose of MISP for small and large security teams
  • Extract attributes, objects, tags, and galaxies from MISP events
  • Investigate a threat based on a high-severity MISP event

Room Prerequisites

Lab Access

For this lab, we will be using a live MISP instance with pre-ingested events.
Click Start Machine, wait a few minutes, and open MISP in your browser by following this link:

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Lab Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Lab machine
Status:Off

Credentials

Use these credentials to access the MISP interface

Username
 
admin@tryhackme.
 
Password
 
nTt21qO8\C.JDrZZ
 
Connection via
 
Web Browser
 
 
Answer the questions below

Continue to the next task.