Windows Quarentine Artifact is no updating the hive case
Closed this issue · 6 comments
hi!
I'm having an issue. Host quarentine works fine, but I cannot make the hive case update. Checking the velociraptor log (eye icon) I see and weird report:
It shows "Url":"https://192.168.232.15/api/case/qGW4VnsBjMFY7TyXP_Zb" insted of "Url":"https://192.168.232.15/**thehive**/api/case/qGW4VnsBjMFY7TyXP_Zb"
any idea?
Hi @marianoka , what URL did you supply for TheHiveURL
?
Hi Wes
Thks for your answer. I'm using this
Server_metadata().thehiveurl
In fact, I didn't edit your code.
Thanks
Well.. I did it. I had to hardcode "thehiveurl" and "thehivekey" values. And also, every time a change is made to an artifact you have to relaunch the monitor. I mean, go to "the eye", unselect "windows.Quarentine" Artificat and launch. And then, do the same, selecting windows.Quarentine and then relaunch all the monitors.
Did you actually populate the URL/Key in the server metadata configuration?
You can edit the details by navigating to $URL/app/index.html#/host/server
.