-
Notifications
You must be signed in to change notification settings - Fork 634
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Feature Request: Case Reporting #305
Comments
I'd like to pump this a bit. Reporting on Cases is one of the most important steps in incident response. Is there something in the works for this? |
Hi @Deastrom, Reporting is indeed very important and something that we will seek to implement by the end of the year. Stay tuned. |
Has anyone been working on this? If not, I'd love to try and work on this. |
Thank you, I'll start working on this now. I'll reach out if I need any help/feedback. |
I'm structuring the layout as follows for now (following the outline by @Deastrom): Case Report
Currently have the report as a button attached to each case (see it here: https://imgur.com/a/BP5eVhT), and this button opens up a modal containing the above information. Planning to have options for the user to select which parts that they want to include in the modal, and have a download button on the bottom. Layout will probably change, but what do you think about this one as a rough draft? @saadkadhi |
Hi @viltaria. Thanks a lot for the proposal. A few comments:
As a next step, the task logs that have been marked for inclusion in the report could be used for #84. @nadouani @jeromeleonard @To-om what's your opinion? |
After some further thought and reviewing my teams current work routine, my plan is to have customizable report templates. People wanting to generate a Case Report would be able to choose between different templates they have previously created to generate a PDF report on their case(s). These templates would be self made, probably in a markdown/html fashion with different case variables accessible through the I believe that this would allow for the flexibility of having to generate multiple types of reports and the different styles needed to support this feature. What do you think? @saadkadhi |
Hi @viltaria , hi @saadkadhi , I would like to contribute to this issue, too. @viltaria could you please share your current work with me? Thanks in advance! In my opinion the specific observable reports that are included should be selectable. This could result in
Furthermore it would be nice if there was an option to add an the logo of your organization to support corporate identity. |
Hi there, currently working on this one. |
Hi everybody, I did some work and finally created a pull request (see #678 ). What did I do?
What needs to be done?
Some thoughts on some decisions:
If there are any questions feel free to ask! |
Hi all! some ideas:
|
@Deastrom @ph34tur3 do you guys want help on this? seems like a great addition to TheHive! you can email me at [email protected]; I have some free time and can get the ball rolling :) for background, I'm an ex-Mandiant consultant who graduated from college a couple months ago |
@veeral-patel : Thanks for considering. I just contacted @nadouani via PR #678 about help on this. |
@nadouani are there any updates on this feature request ? |
I've stopped working on the project, no updates from me |
Case Reporting
Request Type
Feature Request
Work Environment
Problem Description
At the end of a case it will be requested that we provide a report of the case and a print out of the audit log for that case.
Steps to Reproduce
...
Possible Solutions
After the case is complete provide an option to print/report on the case with options to include details such as the audit log. To limit length or provide a good layout it might be best to organize by sections...
Case
Case Details
Case Audit Trail
Tasks in Case
Task Details
Task Logs
Task Attachments
Task Audit Trail
Observeables
Observable Details
Observable Report Findings
Observable Audit Trail
If you were to provide a way to generate this report and offer options for each section (to include gather observable files and attachments in a similar folder structure) then zip it and provide a hash for that zip, this could suffice for reporting purposes, maybe even legal purposes if information on the case is needed for legal proceedings.
Complementary information
I really like what you're doing here and the format is great. I have gotten as far as install TheHive with Cortex and enabling every free Cortex Analyzer I could. My next step will be to set up a Security Onion box and creating a TheHive alert python script. Given the popularity of Security Onion, if there's a good python script out there I can work from, please feel free to send it me way. :)
The text was updated successfully, but these errors were encountered: