You are a Threat Hunter. While investigating, did you find yourself with more than 20 tabs opened in your browser, scattered .txt files with data and some terminals showing up in the background? theTHE centralizes all the information on an investigation in a single project and shares its results with your team (and with nobody else).
theTHE caches your API responses, so you don’t need to repeat the requests. Don’t share your keys, let the users make calls to the services.
theTHE also contains some command-line tools integrated so you don’t have to open a terminal and pipe the results in a .txt file.
Installation
First, clone this repository with:
git clone https://github.com/ElevenPaths/thethe.git
Last, build the images and run the containers
docker-compose up -d
You should see thethe in http://localhost
Also Read – Nginx Log Check : Nginx Log Security Analysis Script
Default User
API Keys
service_name_1,api_value_1
service_name_2,api_value_2
…
service_name_n,api_value_n
What if a service must have more than one API key, secret, etc…
secret,api_value
…
cookie,cookie_value
and so on…
Database Backups & Restoration
MongoDB has a bind volume to ease external storage and backups in a folder mongodb_data
In any case, we have provided you a couple of scripts to backup (a compressed file) and restore data from your mongo container.
Inside utils folder:
Make a backup
backup_thethe_db.sh <mongodb_container_name>
Restore from a backup
restore_thethe_db.sh <mongodb_container_name>
Updating
Make a database backup! (look section “Database backups and restoration”)
git pull
If the source code has been changed all the mounted volumes should reflect the changes, but in certain cases (third party libraries, etc) the images must be rebuilt.
Stop the containers:
docker-compose stop
Rebuild images:
docker-compose build
Restart the system
docker-compose up -d
Development Environment
If you want to collaborate with the project a development version is provided:
Get The Repository
git clone https://github.com/ElevenPaths/thethe.git
Docker
docker-compose -f docker-compose_dev.yml up -d
Run the frontend
cd frontend
npm install
npm run serve
Kali Linux 2024.4, the final release of 2024, brings a wide range of updates and…
This Go program applies a lifetime patch to PowerShell to disable ETW (Event Tracing for…
GPOHunter is a comprehensive tool designed to analyze and identify security misconfigurations in Active Directory…
Across small-to-medium enterprises (SMEs) and managed service providers (MSPs), the top priority for cybersecurity leaders…
The free and open-source security platform SecHub, provides a central API to test software with…
Don't worry if there are any bugs in the tool, we will try to fix…