weslambert/DinoSOARLab

Windows Quarentine Artifact is no updating the hive case

Closed this issue · 6 comments

hi!
I'm having an issue. Host quarentine works fine, but I cannot make the hive case update. Checking the velociraptor log (eye icon) I see and weird report:
It shows "Url":"https://192.168.232.15/api/case/qGW4VnsBjMFY7TyXP_Zb" insted of "Url":"https://192.168.232.15/**thehive**/api/case/qGW4VnsBjMFY7TyXP_Zb"
any idea?

Hi @marianoka , what URL did you supply for TheHiveURL?

Hi Wes
Thks for your answer. I'm using this
Server_metadata().thehiveurl
In fact, I didn't edit your code.
Thanks

Well.. I did it. I had to hardcode "thehiveurl" and "thehivekey" values. And also, every time a change is made to an artifact you have to relaunch the monitor. I mean, go to "the eye", unselect "windows.Quarentine" Artificat and launch. And then, do the same, selecting windows.Quarentine and then relaunch all the monitors.

Did you actually populate the URL/Key in the server metadata configuration?

You can edit the details by navigating to $URL/app/index.html#/host/server.