MISP / misp-book

User guide of MISP
https://www.circl.lu/doc/misp/
256 stars 103 forks source link

Lifecycle documentation of event workflow, inter-analyst workflows etc.. #106

Open philpraxis opened 6 years ago

philpraxis commented 6 years ago

During Hackathon & Training days in Luxembourg in March 2018, we discussed with Andras and Alexandre Dulaunoy about having Sequence Diagrams or other visualization to explain how people work and interact with MISP.

A suggestion is to use Web Sequence Diagrams like markup text to graph / svg / png:

Title: Adding new MISP events

Alice (Org A) -> MISP unpublished: Add event

Note: 
**Any edit/modification on exiting event** puts back the Event in _unpublished mode_.

Alice (Org A) -->> Bob (Org A, Publisher): _Out of band Notification (voice, sms, ...): Please verrify and publish my Event_

MISP unpublished -> Bob (Org A, Publisher): Publish

Bob (Org A, Publisher) -> MISP published: Publish

Note: See **[MISP guide](https://github.com/MISP/MISP/)** for more details

Many tools: Commercial: https://swimlanes.io/#dVBNa4NAEL3vr3hHI0bvOQgWeughTSC9lSLqjjpUd4M72ubfd42Shn7Asiwz72vfC0tHO2Ras2lg6AP7p9MRNJERp1TWcUUIDkODbINtumxHcx7Ljl1L+kpd4Eo9W/FaKgwzcwFplqS3mmuuCmFr4A99ssxGV0IY4jyKQ1lU75CW8DhPwQb5nQO8BuXxryzbNMWDLddBhONKGDY75IdRYGuvbDR8qu8MwWS9SgTXuwhxHHvwsaPCESYaBq4vmCmrOfrLkilX6ufH5zL+s1/fSv0NuPV41+KNsnR4IkIYvl5Rzcia3oJW5Ox2SdKwtGMZV7ZP5vVybXyXtR18VwNBkxTcOfUF

or Free: https://bramp.github.io/js-sequence-diagrams/

screen shot 2018-03-28 at 10 31 24 am screen shot 2018-03-28 at 10 30 12 am

PakitoSec commented 4 years ago

very good idea; if you have already any documentation about this subject I would be very happy to read it;