Tool guide
Step by step walkthroughs for the four tools in every team instance. Get your credentials from the unlock page.
port 9000Case managementThe incident recording, tracking, and management platform. Record incidents a cases, response phases as case tasks, and observables. Two teammates have org admin rights and the other two have read access.
- Log in to TheHive with your responder account.
- At the top right, click the + Create Case button. You will be prompted to choose how to create the case.


- Choose the Empty case option and fill in the case details.
- Click Confirm. The case is created and appears in the case list.



- While viewing the case, open the Tasks tab and click the add task icon.
- Title: name the task after the NIST phase it covers (for example, Detection).
- Description: summarise what your team did in that phase.
- Assignee: the teammate responsible for it.
- Due date: set one if the task is time sensitive.
- Click Confirm.

- The task now shows under the Tasks tab, where you can track and update it.

- Click on Preview on a case task when you hover over it to open it in full and then click on Assignee, and select a team member to assign the task to

- Open the task's ... menu and choose Start when you begin working on that phase.

- The task now shows as Started. When that phase is complete, make sure to open the ... menu again and choose Close before moving on to the next task.

- While viewing the case, open the Observables tab and click the add icon.

- Type: the kind of observable (IP address, URL, domain, file hash, email).
- Value: the actual value, such as an IP address, a URL, or a file hash.
- Description: a short description of the observable.
- Click Save to add it to the case. It now appears in the case's observables list.

This is the final step. Once every case task is closed, all observables are recorded, and all the work in MISP, Cortex and Mattermost is complete, your team concludes the incident by closing the case in TheHive.
- With every task and all tool work finished, click the Close (X) button in the case toolbar at the top right.

- Status: pick the resolution, such as True positive.
- Impact: choose whether there was impact.
- Summary: write the incident resolution summary.
- Click Confirm. The case is now closed and resolved.

port 8080Threat intelligence sharing Correlate IoCs for threat intelligence data. Create security events and add your indicators as attributes. All four teammates are org admins.
- Log in to MISP with your responder account.
- Open the Event Actions menu and choose Add Event.


- Enter the Event Info, Distribution, Analysis, and Threat Level.
- Click Submit.


- After saving the event, you land on the event view.
- Click Add Attribute in the left menu, fill in the details, and submit.


port 9001Observable analysisThe enrichment engine. It runs analysers against observables. All four teammates are org admins here.
- On the top left of the menu pane, click + New Analysis.

- TLP: how the analysis results can be shared.
- PAP: what actions can be taken with the results.
- Data Type: select IP from the dropdown so Cortex knows the observable is an IP address.
- Data: type the IP address you want to analyse.
- Analyzer: select the analyzer to run.

- Click Start to begin. Cortex runs the selected analyzer on the IP address.
- Click View to see the analysis details.


- On the top left of the menu pane, click Job History. Each job is listed with a status such as Waiting, In Progress, or Success.

- When the status changes to Success, click the job to open the detailed results page. The analyzer's report shows detailed intelligence on the observable.


port 8065Team chat & coordinationYour teams communication channel during an incident.
- Log in with your responder email (your username is responder<NN>) and password.
- Join and communicate through your team channel named "RANSOMWARE-INCIDENT"
