Skip to content

Releases: MISP/misp-engineering-bay

Release list

v1.1

Choose a tag to compare

@iglocska iglocska released this 08 Jul 12:26
v1.1
fff6389

MISP Engineering Bay v1.1

image image

Released 2026-07-08 (35 commits since v1.0 (#), 2026-04-06)

This release adds a third tool to the workbench — the Event Template Editor — and hardens the existing tools for real deployments with systemd service
installation, a production WSGI server, and optional HTTPS.

✨ New tool: Event Template Editor

A Python/Flask web app and REST API for authoring MISP event templates (the event-template-v1 construct) — the reusable JSON documents that turn an
incident-response playbook into a single-page form an operator fills to produce a consistently-shaped event.

  • Guided builder — palette + sortable canvas + per-element properties for all 9 element types (section, text_block, attribute_field, object_field,
    tag_field, galaxy_field, file_field, event_report, object_reference).
  • Fully offline, reference-data-backed — attribute category/type, object templates & relations, taxonomies, and galaxies are served from bundled
    submodules and describeTypes.json; no live MISP instance required.
  • Full event_defaults editing — including a guided info_template variable builder and taxonomy/galaxy-backed default pickers.
  • Dual live preview — canonical-JSON view plus a read-only user-form preview that mirrors how MISP renders the template.
  • Two-layer offline validation (structural schema + semantic checks). Export and persist are blocked until the document is valid, so nothing entering the
    library can fail CI.
  • Browse / load / clone / edit the bundled library plus your own drafts.
  • Public/private mode — public for authoring & export, private for direct writes to the misp-event-templates repository.
  • Interactive API docs via Swagger UI, light & dark themes.
  • Backed by 71 tests (structural + semantic validation, reference data, store, end-to-end).

🔧 Operational hardening (existing tools)

Both the Object Template Creator and Galaxy Editor are now deployable as managed services:

  • systemd service installation — install-service.sh + .service.template for one-command setup.
  • Production WSGI serving via gunicorn (gunicorn.conf.py, added to requirements).
  • Dedicated service user account created and used for a saner, least-privilege install.
  • Optional HTTPS — new https block in config.json (enabled / cert_file / key_file).
  • Fixed user-service linger mode requirement so services survive logout.

🐛 Fixes

  • Object Template Creator: address templates by their on-disk directory name rather than their display name. Templates whose directory and JSON name
    differ (e.g. persnona / "Deception PersNOna") can now be loaded, viewed, and cloned correctly, and no longer collide in the listing/dedup logic.

🧹 Housekeeping

  • Submodule URLs switched from SSH to HTTPS (and repo URL pointed at the MISP org) so clones work without SSH keys.
  • Added misp-event-templates and misp-taxonomies submodules; updated misp-objects and misp-galaxy.
  • update-vendor-libs.sh now vendors Swagger UI for all three tools.