5.6.30. `Admin-GCenter- Third-party modules` screen of the legacy web UI

See presentation of Intelligence site and GBox.
After pressing the `Third-party modules` of the menu `Admin-GCenter`, a screen of choice is displayed.
This screen allows you to configure connections with GCenter-related servers:
  • Connection to a MISP server

  • Login to intelligence website

  • Connection to local GBox

Party

Function

See

`MISP`

Configuring the connection to a MISP server

MISP Connection Configuration Screen

`Intelligence`

Configuration of the connection to the Intelligence site or GBox

Intelligence site and GBox login configuration screen


5.6.30.1. MISP Connection Configuration Screen

This screen is used to manage the connection between the GCenter and a Malware Information Sharing Platform (MISP) server in the local infrastructure.
After pressing the `MISP` button of the `Third-party modules` screen, the following screen is displayed:
../../_images/GCENTER-MISP-01.PNG

The `MISP settings` screen contains the following parts:

Item

Name

Function

1

zone `Resume`

This zone indicates the connection status with the MISP. It includes:

2

  • status message

Connection status message with remote server
For example: `MISP has never been configured`

3

zone `MISP Settings`

This zone enables setting the connection. It includes:

4

  • `Enable MISP features`

This area allows setting the connection. The area includes:
This button displays the `MISP` command from the `Config / Sigflow` menu for configuring rule updates

5

  • `Disable TLS verification`

TLS verification disable button

6

  • `Protocol`

Communication protocol to be used to contact the MISP instance. Two options are possible: 'https' and 'http'

7

  • `Port`

MISP instance listening port

8

  • `MISP Api key `

MISP instance API key

9

  • `MISP instance IP or FQDN`

Domain name or IP address of the MISP instance

10

  • `Output interface`

GCenter network interface for connection with MISP server

11

  • `Save`

Save Entered Parameters button

For implementation, see the Configuring the connection to the MISP.


5.6.30.2. Intelligence site and GBox login configuration screen

For more information on the functions of these elements, see the presentation of Intelligence site and GBox.
The connection between the GCenter and the Intelligence site (or GBox) requires configuration.
The parameters of this configuration are accessible in the `Interconnection settings` screen.
After pressing the `Intelligence` button on the `Third-party modules` screen, the following screen is displayed:
../../_images/INTELLIGENCE-01.PNG

The Interconnection settings page consists of 2 tabs:

  • `CONFIGURATION` Settings Management tab

  • `SECURITY` Settings Management tab

For implementation of the configuration to the Intelligence site, refer to Configuring the connection to the Intelligence site.
For the implementation of the configuration to the GBox, refer to Configuring the connection to the GBox.

5.6.30.2.1. Tab `CONFIGURATION`

After pressing the `CONFIGURATION` button on the `Interconnection settings` screen, the following screen is displayed:

../../_images/INTELLIGENCE-01.PNG

The `CONFIGURATION` tab contains the following parts:

Item

Nom

Function

1

`CONFIGURATION`

This button displays the following configuration information:

3

  • `Intelligence usermail`

Email address of the intelligence account to which an email will be sent.
This contains a token to connect a GCenter to https://intelligence.GATEWATCHER.com/packages/list/

4

  • `Interface`

GCenter network interface to communicate with the Intelligence / GBox site

5

  • `Save`

Save Entered Parameters button

6

  • `Test the interconnection...`

Test button for the interconnection with the saved parameters. The result is given by a message.
For example, the message `Successfully established connection to GBox https://x.x.x.x` is displayed to indicate a correct connection with a GBox.

7

  • status message

Connection status message with remote server

8

  • `Analysis mode`

Analysis mode: Online (Intelligence) or Offline (GBox)

9

  • `Url`

Url of the remote server. For the GBox, https://x.x.x.x or the Gatewatcher Intelligence server address (https://intelligence.GATEWATCHER.com/gwapi/)

10

  • `Enable interconnection`

Button to activate connection

11

  • `Is the target server a GBOX`

Button to be activated only for GBox

2

`SECURITY`

This button displays the information required for security: this information is detailed below


5.6.30.2.2. Tab `SECURITY`

After pressing the `SECURITY` button on the `Interconnection settings` screen, the following screen is displayed:

../../_images/INTELLIGENCE-02.PNG

The `SECURITY` tab contains the following parts:

Item

Name

Function

1

`CONFIGURATION`

This button displays the information needed for configuration: this information is detailed above

2

`SECURITY`. This button displays the information necessary for security:

3

  • `Save`

Save button for entered parameters

4

  • `Test the interconnection....`

Test button for interconnection with saved parameters. The result is given by a message.
For example, the message `Successfully established connection to GBox https://x.x.x.x` is displayed to indicate a correct connection with the GBox

5

  • status message

Connection status message

6

  • `Token`

Token generated on the remote server. This token is generated on the GBox or received by email for access to the Intelligence site.

7

  • `Private remote analysis`

`Private remote analysis` selector allows anonymity when sending samples

8

  • `Disable SSL verification`

Allows use of self-signed certificate: to be used only for GBox