Skip to content
Guide d'utilisation

Guide d'utilisation

github.com • October 8, 2026

Installation Pre-requisites Supported Platforms Hardware Software Installing pre-requisites Procedure for installing GitHub After installation

Pre-requisites Supported Platforms Hardware Software Installing pre-requisites

Installing pre-requisites

Procedure for installing GitHub

The Nethive Project provides a Security Information and Event Management (SIEM) insfrastructure empowered by CVSS measurements. This infrastructure offers zero to no latency vulnerability monitoring, and has been empowered by ELK Infrastructure as well. The infrastructure prioritzes flexibility, as we construct the infrastructure with plug-and-play engines through Docker. We also use Kafka server to relay event messages between engines, making it lightning fast in terms of event data relaying. The infrastructure has 4 different components backboning it.

Nethive Engine monitors every request coming through HTTP protocol to detect and identify any attempt of SQL Injection attacks. It also anonymously monitors every SQL query response to provide a wide range of XSS protection for your server, with both Stored and Reflected XSS attacks fully covered.

Nethive Auditing watch everything that happens inside your valuable system, with your permission of course. This would detects any strange and suspicious activity inside the system, whether it is a post-exploitation attempt of an attacks, or simply someone you trust is making mistake inside your system.

Nethive Dashboard provides you with resourceful, sleek user inferface that gives you the advantage of knowing everything. From resource consumption to the recent read-write action, it gives you full detail of what's happening, in near real-time.

Nethive CVSS analyze the unfortunately already happening attacks and measure its vulnerability metrics, making sure you are ready to put your reports done in no time.

Nethive Project runs on Linux operating systems. It is compatible with Python 3.

Linux OS / Raspberry Pi - have sudo access on the terminal/console

Mouse / Wireless Mouse / Touchpad congenital laptop

Installing pre-requisites

Python:

Alternatively, you can follow the instructions provided on the official website:

Auditbeat: See Filebeat

Packetbeat: See Filebeat

Docker:

Installation example for Ubuntu 18.04 :

Docker-Compose:

Installation from Github

Installing from GitHub involves the following steps:

Clone the repository: $ git clone

Clone the repository: $ git clone

Navigate into the project directory: $ cd Nethive-Project/

Navigate into the project directory: $ cd Nethive-Project/

Install library dependencies: $ sudo bash install.sh

Install library dependencies: $ sudo bash install.sh

Install Python dependencies: $ sudo python3 -m pip install -r requirements.txt

Install Python dependencies: $ sudo python3 -m pip install -r requirements.txt

Install Nethive package: $ sudo python3 setup.py install

Install Nethive package: $ sudo python3 setup.py install

If done, proceed to After installation

Configuring Nethive environment

Nethive configuration should be stored in a file named .env and located on the root directory of the project.

Copy .env.example to .env $ cd Nethive-Project/ $ cp .env.example .env

Edit using gedit: $ gedit .env

Save your changes and proceed to section.

Default configuration:

Running Nethive after configuration change

Nethive depends on some third party binaries, such as: Filebeat, Auditbeat, etc., and requires special configuration for some services, such as MySQL server, etc. When running for the first time, you need to make sure that those binaries and services are configured to work with Nethive .

Important! Nethive needs a sudo permission to work.

Important! Nethive needs a sudo permission to work.

Start Nethive with superuser permission: $ sudo python3 main.py

On the prompt, choose: [2] Refresh Configuration to apply your modified .env configuration into the Nethive itself and to distribute Nethive-ready configuration for the third party dependencies (beats, etc.).

[Command preview GIF]

Nethive-cvss is a low-latency, CVSS Summarizer that allows for quick estimation of risk from an event that is classified as a threat by the SIEM engine. The output of this summarizer is shaped in the following format

Nethive-CVSS requires a Kafka server to run, which is already provided inside the Nethive Engines in the form of Docker Container when you clone this repository.

Required Env Variables

You would need to configure a MYSQL server, a table called paths must be inserted in your specified database with the following columns

The Nethive-CVSS microservice requires you to specify several environment variables in order to work. The following is the list of envionment variables

And the rest, is taken care for y

This microservice is required so that every detected attacks are measured automatically according to CVSS3.0 vulnerability measurement. A Nethive Engine will automatically send every detected attacks data into this docker container and the measurement result will be stored back into Elasticsearch to a specified index.

To run nethive-cvss docker:

You know, just an ordinary exit . Meh.