Releases: MISP/misp-engineering-bay
Releases · MISP/misp-engineering-bay
Release list
v1.1
MISP Engineering Bay v1.1
Released 2026-07-08 (35 commits since v1.0 (#), 2026-04-06)
This release adds a third tool to the workbench — the Event Template Editor — and hardens the existing tools for real deployments with systemd service
installation, a production WSGI server, and optional HTTPS.
✨ New tool: Event Template Editor
A Python/Flask web app and REST API for authoring MISP event templates (the event-template-v1 construct) — the reusable JSON documents that turn an
incident-response playbook into a single-page form an operator fills to produce a consistently-shaped event.
- Guided builder — palette + sortable canvas + per-element properties for all 9 element types (section, text_block, attribute_field, object_field,
tag_field, galaxy_field, file_field, event_report, object_reference). - Fully offline, reference-data-backed — attribute category/type, object templates & relations, taxonomies, and galaxies are served from bundled
submodules and describeTypes.json; no live MISP instance required. - Full event_defaults editing — including a guided info_template variable builder and taxonomy/galaxy-backed default pickers.
- Dual live preview — canonical-JSON view plus a read-only user-form preview that mirrors how MISP renders the template.
- Two-layer offline validation (structural schema + semantic checks). Export and persist are blocked until the document is valid, so nothing entering the
library can fail CI. - Browse / load / clone / edit the bundled library plus your own drafts.
- Public/private mode — public for authoring & export, private for direct writes to the misp-event-templates repository.
- Interactive API docs via Swagger UI, light & dark themes.
- Backed by 71 tests (structural + semantic validation, reference data, store, end-to-end).
🔧 Operational hardening (existing tools)
Both the Object Template Creator and Galaxy Editor are now deployable as managed services:
- systemd service installation — install-service.sh + .service.template for one-command setup.
- Production WSGI serving via gunicorn (gunicorn.conf.py, added to requirements).
- Dedicated service user account created and used for a saner, least-privilege install.
- Optional HTTPS — new https block in config.json (enabled / cert_file / key_file).
- Fixed user-service linger mode requirement so services survive logout.
🐛 Fixes
- Object Template Creator: address templates by their on-disk directory name rather than their display name. Templates whose directory and JSON name
differ (e.g. persnona / "Deception PersNOna") can now be loaded, viewed, and cloned correctly, and no longer collide in the listing/dedup logic.
🧹 Housekeeping
- Submodule URLs switched from SSH to HTTPS (and repo URL pointed at the MISP org) so clones work without SSH keys.
- Added misp-event-templates and misp-taxonomies submodules; updated misp-objects and misp-galaxy.
- update-vendor-libs.sh now vendors Swagger UI for all three tools.