Sighting searches in MISP
You can perform sighting searches on observables in the MISP instance to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL, occur in your network. Each occurrence is considered a sighting.
Sightings in MISP
Some attributes are considered as false positives, which means that they are not valid sightings. Other attributes are valid for only a certain duration, such as a phishing campaign that runs for only one week. You can assign an expiration date to the attributes that are valid for a certain duration, but each organization can assign only one valid expiration date to an attribute.
Sightings that are created in MISP by users of organizations that are marked as local in the corresponding MISP server are known as internal sightings. Sightings that are created in MISP by users of organizations that are marked as remote in the corresponding MISP server are known as external sightings.
Sighting searches in SIR
The Security Operations Integration - Sightings Search workflow executes the sightings search. This flow accepts a list of observables, finds any implementing capabilities, creates the queries that are based on the sighting search configurations, and executes the searches that are based on the configured flow.
Sighting searches helps analysts to determine the prevalence of a threat over time. You can select individual or multiple observables and the date range for your search from a security incident. Results are included in the Security Incident Sightings, Sightings Search Results, and Sightings Search Details related lists.
As you start to analyze an incident, you can set up your ServiceNow AI Platform to automatically perform a sightings search or manually perform an observable sightings search to identify other users in your organization who are impacted by the same phishing attack.
Enable automatic sighting searches in MISP
Enable the sighting search in MISP to run automatically so that the Security Operations Integration - Sightings Search workflow is triggered whenever new observables are associated with a security incident.
Before you begin
Verify that the Sightings Search Configuration profile for MISP is active.
Role required: sn_si.analyst
About this task
Procedure
Perform a manual sighting search in MISP
Select individual or multiple observables and perform a manual sighting search in the ServiceNow AI Platform MISP integration for Security Operations application to determine the prevalence of a threat over time.
Before you begin
- Review the MISP user role and permissions for using the MISP bi-directional features.
- Role required: sn_si.analyst
Procedure
Result
Report sightings to MISP
Report threat data sightings so that you can react to false positives in your data and increase your awareness when a true positive threat occurs. You can also add an expiration date for a particular observable or attribute.
Before you begin
- Review the MISP user role and permissions for using the MISP bi-directional features.
- Role required: sn_si.analyst
About this task
To report a sighting to MISP, the observable or the attribute must be available in the MISP instance.