網絡安全事件管理平臺:Fast Incident Response

jopen 8年前發布 | 17K 次閱讀 Django 安全相關

What is FIR? Who is it for?

FIR (Fast Incident Response)一個網絡安全事件管理平臺,專注于敏捷和速度。它可以輕松創建,跟蹤和報告的網絡安全事件。

FIR is for anyone needing to track cybersecurity incidents (CSIRTs, CERTs, SOCs, etc.). It's was tailored to suit our needs and our team's habits, but we put a great deal of effort into making it as generic as possible before releasing it so that other teams around the world may also use it and customize it as they see fit.

See the wiki for theuser manual and more screenshots !

Installation

There are two ways to install FIR. If you want to take it for a test-drive, just follow the instructions for setting up a development environment in the Wiki.

If you like it and want to set it up for production,here's how to do it.

A dockerfile for running a dev-quality FIR setup is also available indocker/Dockerfile.

Technical specs

FIR is written in Python (but you probably already knew that), using Django 1.7.6. It uses Bootstrap 3 and some Ajax and d3js to make it pretty. We use it with a MySQL back-end, but feel free to use any other DB adaptor you might want - as long as it's compatible with Django, you shouldn't run into any major issues.

FIR is not greedy performance-wise. It will run smoothly on a Ubuntu 14.04 virtual machine with 1 core, a 40 GB disk and 1 GB RAM.

Roadmap

  • Nested Todos
  • REST API
  • Mailman
  • You name it :)

來自: https://github.com/certsocietegenerale/FIR

 本文由用戶 jopen 自行上傳分享,僅供網友學習交流。所有權歸原作者,若您的權利被侵害,請聯系管理員。
 轉載本站原創文章,請注明出處,并保留原始鏈接、圖片水印。
 本站是一個以用戶分享為主的開源技術平臺,歡迎各類分享!