/capes

Cyber Analytics Platform and Examination System (CAPES) Project Page

Primary LanguageCSSApache License 2.0Apache-2.0

Cyber Analytics Platform and Examination System (CAPES)

capes logo

People ask from time-to-time what help is needed - documentation. If you see documentation that is wrong, be it grammar, incorrect guidance, or missing; please consider doing a PR correcting it. I will gladly give contributor status to anyone who does anything to make this project easier for people to get started.

CAPES is an operational-focused service hub for segmented, self-hosted, and offline (if necessary) incident response, intelligence analysis, and hunt operations.

capes architecture

Services in CAPES

  1. Mattermost (Chat)
  2. HackMD (Collaboration-style documentation)
  3. Gitea (Version controlled documentation)
  4. TheHive (Incident Response)
  5. Cortex (Indicator enrichment)
  6. CyberChef (Data analysis)
  7. Mumble (VoIP)
  8. Beats - Metric, Heart, and File (Performance and health metrics)
  9. Kibana (Data visualization)

Roadmap

  1. Documentation
  2. Convert CAPES to Docker *

Note

* designates current effort

Documentation / Installation

See docs for detailed instructions.

CentOS 7.4

$ sudo yum -y install git
$ git clone https://github.com/capesstack/capes.git
$ cd capes
$ sudo sh deploy_capes.sh

Pre-CentOS 7.4

$ sudo yum install -y https://kojipkgs.fedoraproject.org/packages/http-parser/2.7.1/3.el7/x86_64/http-parser-2.7.1-3.el7.x86_64.rpm
$ sudo yum -y install git
$ git clone https://github.com/capesstack/capes.git
$ cd capes
$ sudo sh deploy_capes.sh

Get Started

After the CAPES installation, you should be able to browse to http://your_capes_system (or http://your_capes_IP if you don't have DNS set up) get get to the CAPES landing page and start setting up services by following the post installation steps.

Although most of these services are fairly intuitive, I strongly recommend that you look at the Build, Operate, Maintain guides for these services before you get going too far. A few of the services launch a configuration pipeline that is obnoxious to restart if you don't complete it the first time (I'm looking at you TheHive and Gitea).

Troubleshooting

Please see the documentation or feel free to open a GitHub Issue.

You can run $ capes_processes to make sure all of your processes are running.

Want to join the discussion? Send a request to join our Slack Workspace to contact [at] capesstack[.]io

Swag

Interested in some CAPES swag? Send me a email to contact [at] capesstack[.]io and I'll send you some laptop decals.

If you're interested in CAPES t-shirts, we parter with TeeSpring for those. Feel free to check out our storefront. We don't make a penny on these - 100% of the profits go to the National Alliance to End Homelessness.

Training & Professional Services

While CAPES is a FOSS project and we'll attempt to support deployment questions via the Issues page, if you need training or PS, please feel free to check out some options over at Perched