Installation Pre-requisites Supported Platforms Hardware Software Installing pre-requisites Procedure for installing GitHub After installation
Pre-requisites Supported Platforms Hardware Software Installing pre-requisites
Installing pre-requisites
Procedure for installing GitHub
The Nethive Project provides a Security Information and Event Management (SIEM) insfrastructure empowered by CVSS measurements. This infrastructure offers zero to no latency vulnerability monitoring, and has been empowered by ELK Infrastructure as well. The infrastructure prioritzes flexibility, as we construct the infrastructure with plug-and-play engines through Docker. We also use Kafka server to relay event messages between engines, making it lightning fast in terms of event data relaying. The infrastructure has 4 different components backboning it.
Nethive Engine monitors every request coming through HTTP protocol to detect and identify any attempt of SQL Injection attacks. It also anonymously monitors every SQL query response to provide a wide range of XSS protection for your server, with both Stored and Reflected XSS attacks fully covered.
Nethive Auditing watch everything that happens inside your valuable system, with your permission of course. This would detects any strange and suspicious activity inside the system, whether it is a post-exploitation attempt of an attacks, or simply someone you trust is making mistake inside your system.
Nethive Dashboard provides you with resourceful, sleek user inferface that gives you the advantage of knowing everything. From resource consumption to the recent read-write action, it gives you full detail of what's happening, in near real-time.
Nethive CVSS analyze the unfortunately already happening attacks and measure its vulnerability metrics, making sure you are ready to put your reports done in no time.
Nethive Project runs on Linux operating systems. It is compatible with Python 3.
Linux OS / Raspberry Pi - have sudo access on the terminal/console
Mouse / Wireless Mouse / Touchpad congenital laptop
Installing pre-requisites
Python:
Alternatively, you can follow the instructions provided on the official website:
Packetbeat: See Filebeat
Installation example for Ubuntu 18.04 :
Docker-Compose:
Installation from Github
Installing from GitHub involves the following steps:
Clone the repository: $ git clone
Clone the repository: $ git clone
Navigate into the project directory: $ cd Nethive-Project/
Navigate into the project directory: $ cd Nethive-Project/
Install library dependencies: $ sudo bash install.sh
Install library dependencies: $ sudo bash install.sh
Install Python dependencies: $ sudo python3 -m pip install -r requirements.txt
Install Python dependencies: $ sudo python3 -m pip install -r requirements.txt
Install Nethive package: $ sudo python3 setup.py install
Install Nethive package: $ sudo python3 setup.py install
If done, proceed to After installation
Configuring Nethive environment
Nethive configuration should be stored in a file named .env and located on the root directory of the project.
Copy .env.example to .env $ cd Nethive-Project/ $ cp .env.example .env
Edit using gedit: $ gedit .env
Save your changes and proceed to section.
Default configuration:
Running Nethive after configuration change
Nethive depends on some third party binaries, such as: Filebeat, Auditbeat, etc., and requires special configuration for some services, such as MySQL server, etc. When running for the first time, you need to make sure that those binaries and services are configured to work with Nethive .
Important! Nethive needs a sudo permission to work.
Important! Nethive needs a sudo permission to work.
Start Nethive with superuser permission: $ sudo python3 main.py
On the prompt, choose: [2] Refresh Configuration to apply your modified .env configuration into the Nethive itself and to distribute Nethive-ready configuration for the third party dependencies (beats, etc.).
[Command preview GIF]
Nethive-cvss is a low-latency, CVSS Summarizer that allows for quick estimation of risk from an event that is classified as a threat by the SIEM engine. The output of this summarizer is shaped in the following format
Nethive-CVSS requires a Kafka server to run, which is already provided inside the Nethive Engines in the form of Docker Container when you clone this repository.
Required Env Variables
You would need to configure a MYSQL server, a table called paths must be inserted in your specified database with the following columns
The Nethive-CVSS microservice requires you to specify several environment variables in order to work. The following is the list of envionment variables
And the rest, is taken care for y
This microservice is required so that every detected attacks are measured automatically according to CVSS3.0 vulnerability measurement. A Nethive Engine will automatically send every detected attacks data into this docker container and the measurement result will be stored back into Elasticsearch to a specified index.
To run nethive-cvss docker:
You know, just an ordinary exit . Meh.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
