theTHE : The Threat Hunting Environment

You are a Threat Hunter. While investigating, did you find yourself with more than 20 tabs opened in your browser, scattered .txt files with data and some terminals showing up in the background? theTHE centralizes all the information on an investigation in a single project and shares its results with your team (and with nobody else).

theTHE caches your API responses, so you don’t need to repeat the requests. Don’t share your keys, let the users make calls to the services.

theTHE also contains some command-line tools integrated so you don’t have to open a terminal and pipe the results in a .txt file.

Installation

First, clone this repository with:

git clone https://github.com/ElevenPaths/thethe.git

Last, build the images and run the containers

docker-compose up -d

You should see thethe in http://localhost

Also Read – Nginx Log Check : Nginx Log Security Analysis Script

Default User

  • By default, there is only one user admin with password admin
  • Change the admin password as soon as you login into thethe the very first time.

API Keys

  • There are not API keys stored by default in the system.
  • To add an API key, there is an option in the user menu (right upper corner).
  • All API keys (a new API management system is in development) must be written as CSV values:

service_name_1,api_value_1
service_name_2,api_value_2



service_name_n,api_value_n

What if a service must have more than one API key, secret, etc…

secret,api_value



cookie,cookie_value

and so on…

Database Backups & Restoration

MongoDB has a bind volume to ease external storage and backups in a folder mongodb_data

In any case, we have provided you a couple of scripts to backup (a compressed file) and restore data from your mongo container.

Inside utils folder:

Make a backup

backup_thethe_db.sh <mongodb_container_name>

Restore from a backup

restore_thethe_db.sh <mongodb_container_name>

Updating

Make a database backup! (look section “Database backups and restoration”)

git pull

If the source code has been changed all the mounted volumes should reflect the changes, but in certain cases (third party libraries, etc) the images must be rebuilt.

Stop the containers:

docker-compose stop

Rebuild images:

docker-compose build

Restart the system

docker-compose up -d

Development Environment

If you want to collaborate with the project a development version is provided:

Get The Repository

git clone https://github.com/ElevenPaths/thethe.git

Docker

docker-compose -f docker-compose_dev.yml up -d

Run the frontend

cd frontend
npm install
npm run serve

R K

Recent Posts

Install Pip on Ubuntu 18.04: Python 3 and Python 2 Setup Guide

Pip is the official package manager for Python and the standard way to install libraries from…

20 hours ago

Install R on Ubuntu 18.04 from CRAN: Statistical Computing Setup

R is an open-source programming language and environment built for statistical computing and data visualization. It…

20 hours ago

Install Jenkins on Ubuntu 18.04: CI/CD Server Setup Guide

Jenkins is an open-source automation server that makes it easy to build CI/CD pipelines. Continuous integration…

20 hours ago

Install Android Studio on Ubuntu 18.04 with Snap and OpenJDK 8

Android Studio is the official IDE for Android development, built on JetBrains' IntelliJ IDEA platform. It…

20 hours ago

Install and Configure GitLab on Ubuntu 18.04 with Omnibus

GitLab is a web-based, open-source Git repository manager written in Ruby. It includes built-in tools for…

20 hours ago

Install Anaconda on Ubuntu 18.04: Python Data Science Setup Guide

Anaconda is the most widely used Python distribution for data science and machine learning. It bundles…

2 days ago