-
Notifications
You must be signed in to change notification settings - Fork 17
Admin Configure
The settings of Taranis can be configured through the Taranis web interface or via the configuration files on the Taranis server. This chapter describes the different web-based configuration options Taranis offers.
The configuration of Taranis is opened through the “Configuration” link on top of every page. This chapter will focus on these configuration items only. It depends on the user's rights which configuration options are displayed.
Figure: Configuration options
Taranis uses the concept of Constituents. Constituents can be seen as customers of the security team. Constituent individuals are grouped into Constituent groups. Constituent groups are usually organizations within the constituency, whereas Constituent individuals are the employees of these organizations. Each Constituent group is of a specific Constituent type. The type of Constituent dictates what kind of products this Constituent group is allowed to receive.
The rest of this chapter will go into detail on the different aspects surrounding Constituents.
Users can define different Constituent types through the ‘Constituent Types’ option in the Configuration menu. Enter a name for a Constituent type and assign publication types to it. As described in further down in this chapter, linking publication types to a Constituent type will have a great impact on the publication types that Constituent individuals will be able to receive.
NOTE: Taranis will warn you when you unlink a publication type from a Constituent type because this will break all links between Constituent individuals and publication types for all Constituent groups that are assigned to this specific Constituent type.
Each Constituent individual has a role. This role describes the type of contact person this individual is to your organization. Examples of this role are: “operational contact” or “contract owner”. You can configure the Constituent role in the Constituent Roles configuration item. Each entry in this configuration item contains only one value. The possible values are given as the Role options in the Constituent individual information screen.
You can manage the Constituent groups by choosing ‘Constituent groups’ from the Configuration menu. The figure below shows the information displayed for Constituent groups.
Figure: Management of Constituent groups
If you have a lot of Constituent groups configured, you can search through them based on Constituent type, keyword or status. For every Constituent group, the name of this group is shown. To the right of the Constituent group, a maximum of four action icons is displayed. The user can edit the Constituent group by clicking on the first icon. The second icon will give you an overview of this specific Constituent group, including Constituent individuals that are linked to this Constituent group. Clicking the third icon will delete the specific Constituent group.
The phone icon does not have any action configured with it, but is simply an indicator that this Constituent group will have to be called in case of a high/high advisory.
When you edit a Constituent group or add a new Constituent group (by clicking on the Add new button), the details window for Constituent groups is opened. This window has four tabs to manage the different properties of a Constituent group.
General settings
The ‘General settings’ tab allows you to administer general properties of the Constituent group. An example of these properties:
Figure: Constituent group properties
Many of the properties are pretty straight forward: you can edit the name, the type, and the current status of the Constituent group. The list of Constituent types available is based on the list of types you configured. The configured Constituent type defines what kind of publications the members of this group will be allowed to receive.
You must also indicate whether or not to use the software/hardware list (‘Software/Hardware list in use’) of this Constituent group. If you choose ‘Yes’, this Constituent group will only receive those advisories that are linked to hardware and software that are on the software/hardware list of this Constituent group. If you choose ‘No’, the software/hardware list will be ignored, which results in the Constituent group receiving all advisories.
The ‘Call for H/H incident’ property indicates whether or not the Constituent group wishes to be called in case of an advisory that has high chance and high impact. If you choose ‘Yes’, the Constituent group will automatically be added to the calling list of such an advisory.
Configuring Constituent group members
The ‘Members’ tab allows users to link Constituent individuals to Constituent groups. On the right side of this tab, a list of all configured Constituent individuals is displayed. By selecting one or more Constituent individuals and then clicking the < button, Taranis will link the individuals to the group. You can select more Constituent individuals at once by holding down the [Ctrl]-key while selecting or double clicking on a specific Constituent individual to only select that individual. Please note that it is possible to add a Constituent individual to multiple groups.
Populating the software/hardware list
Taranis supports the use of CPE to populate a list of possible hard- and software in use by Constituent groups. The ‘Software/Hardware’ tab enables users to link hard- and software from this list to a Constituent group. By linking hard- and software to Constituent groups it is possible to only send relevant advisories to this Constituent group.
You can link hard- and software by searching through the soft-/hardware list and then selecting all relevant items. Again, clicking the button (or double clicking on an item) will link the selected hard- and software to the group.
Figure: Populating the hard-/software list of a Constituent group
Notes
You can add notes to a Constituent group. These notes enable users to record unstructured information about the Constituent. The notes show in a high/high caller list so that any particulars about the Constituent group is automatically presented to the person responsible for informing this group.
As described in the previous paragraph, Constituent individuals are part of a Constituent group. Constituent individuals can be managed by selecting the ‘Constituent individuals’ option from the Configuration menu.
Figure: Management of Constituent individuals
The action icons for each Constituent individual works basically the same as for the Constituent groups described in the previous paragraph: the user can edit the Constituent individual by clicking on the icon and delete the Constituent individual by clicking on the icon. The icon is again an indicator that this Constituent individual will have to be called in case of a high/high advisory. Hovering your mouse pointer over the icon allows you to quickly see the main information about this individual.
When you edit a Constituent individual or create a new one, Taranis will open the Constituent individual details window. Split across three tabs, this window allows the user to specify individual properties, link the individual to Constituent groups, and specify the publication types the individual wishes to receive.
Individual details
The ‘Individual details’ tab enables the user to record contact information for this individual (e-mail, phone) and the role of the user. Regarding the preferences for contact over the phone in case of high/high advisories, the user cannot only specify whether the individual wants to be called, but also if he wants to be called outside office hours. Taranis will use these settings when it creates a calling list for a specific high/high advisory.
Constituent role
Each individual has a role. This role describes the type of contact this individual is to your organization. Examples of this role are: “operational contact” or “contract owner”. You can configure the Constituent role in the Constituent Roles configuration. Each entry in this configuration contains only one value. The possible values are given as the Role options in the Constituent individual information screen.
Specifying publication types
You can define which publication types a user wishes to receive. The publication types available depend on the Constituent group(s) the individual is a member of, the type of these Constituent group(s) and the publication types linked to these Constituent types.
Figure: Publication types for an individual
Taranis currently supports the following publication types:
- Advisory (email)
- an email with the advisory text, without an XML-based version of the advisory attached to it.
- Advisory (XML)
- an email with the advisory text, with an XML-based version of the advisory attached to it. Based on the “advisory (email)”.
- Advisory (forward)
- a separate advisory product, which consists of a “raw” original (vendor) advisory along with added metadata.
- End-of-Shift (email)
- an email with the end-of-shift.
- End-of-Week (email)
- an email with the end-of-week.
The list of hard- and software in use by constituents is called the ‘photo’. This is a historic term used by NCSC-NL that might lead to some confusion. It refers to the ‘snapshot’ of used hard- and software by a constituent.
You can import and export these lists through the Taranis web interface.
Import photo
Change a list of software and hardware used by a constituent via the Taranis GUI based by uploading a CSV file. Taranis will link all the soft- and hardware in that file to the constituent you specify.
The CSV file you specify must contain all the soft- and hardware you want to import, one component per line. Each component must be defined as producer, soft-/hardware name, soft-/hardware type and CPE-ID, divided by colons, for example:
"3Com","Router 5231","cpe:/h:3com:3c13750","Hardware"You start the import-process by clicking the button in the Photo management-section. Next, the ‘Import photo’ screen will open. This screen allows you to import a photo and get an overview of all the previous imports.
Figure: Import photo
The list of imports shows the Constituent group for which a photo was imported, the time the import was created and the time the import was finalized (‘imported on’). For all pending imports (imports that still have issues), the ‘imported on’ property is empty. You can open such an import by clicking on the Constituent group name.
You start an import by selecting a Constituent group from the dropdown list and browsing for a CSV file. All Constituent groups, for which an import is pending, will not show up in the dropdown list. This is to prevent concurrency issues.
Once you have selected a Constituent group and a CSV file, click on the button to start the import. If the CSV is properly structured, you get an overview of the items to be imported as follows:
Figure: Items to be imported
Different colors indicate whether attention is needed before the import of the item can be executed. Items are colored white, green, light orange or dark orange.
White indicates that the item is already on the Constituents photo. Green indicates that the item can be linked to the Constituent group with no extra attention. Orange indicates that the user must consider creating an issue for this item and red indicates that the item cannot be linked to the Constituent group because the hard-/software could not be found.
Depending on the status (color) of the item, you can perform different actions:
- Accept the import of the item. The item will be linked to the Constituent group.
- Create an issue for this item. An issue means that further action needs to be taken before this item can be linked to the Constituent group. Possible actions include: finding a source to be able to monitor vulnerabilities in this product, or creating a new soft- or hardware item in case the item is not part of the current soft-/hardware list.
- Remove the item from the import-list. The item will not be linked to the Constituent group and an issue will be created.
| CPE-match | Exact match | In use | |
|---|---|---|---|
| Yes | Yes | Yes | Taranis found a match on both CPE-ID and name. This product is already in use by another Constituent so it is safe to link this item |
| Yes | Yes | No | Although Taranis found a match on both CPE-ID and name, attention is required because this product isn’t used by any of the other Constituents. |
| Yes | No | Yes | Taranis found a match based on CPE-ID and the product is already in use. We can link it without intervention. |
| Yes | No | No | Taranis found a match based on CPE-ID but the product is not in use by any of the other Constituents. |
| No | Yes | Yes | Taranis found a match (based on name) and this product is in use by at least one of the other Constituents. It is safe to link without intervention. |
| No | Yes | No | Taranis found a match (based on name) but this product is not yet in use by any of the other Constituents. |
| No | No | Yes | This situation cannot occur: a product that is in use but is not listed in the soft-/hardware list. |
| No | No | No | The product is not known by Taranis. You must first add a new item to the soft-/hardware list before you can import this item. |
Every import will most probably result in issues that need to be resolved before the list can be linked to the Constituent group. The list of all open issues can be seen by just opening Photo management again. All open issues are indicated with a red background:
Figure: Open issues
You must resolve all open issues before you can actually import the photo of the Constituent. If no match was found for a particular software item you must first add a new item to the hard-/software list, and then reopen the issue. You can then link the issue to the new soft-/hardware item just created and then resolve the issue as illustrated in
Figure: Resolve issue
Taranis remembers the choices you make. This means that an item you resolve will automatically be resolved in future imports when the same item shows up in this import.
Special attention is required if you add an item to a photo that is not yet in use by any of the other Constituents. In this case you must make sure that you have proper sources in Taranis to monitor for new vulnerabilities in that product. You must resolve these issues by following a workflow that mostly resembles the workflow of publications: add your comments, set the issue to Ready for review, and Accept & resolve the issue.
Figure: Accept and resolve issue
Export empty photo
You can export the list of soft- and hardware by clicking from within Photo management. This will present you with a comma separated file that lists the following information of all soft- and hardware:
- Producer (vendor), e.g. ‘Oracle’.
- Product, e.g. ‘PeopleSoft Enterprise’.
- CPE-ID (if applicable), e.g. ‘cpe:/a:oracle:peoplesoft_enterprise’.
- Soft-/hardware type, e.g. ‘Application.
You can send the soft-/hardware list to your constituents so that they can specify which products they use. The Constituent must then create a new CSV file in which only the products they use are listed. This file can then be imported through the ‘Photo import’ functionality (see previous section).
Export all products in use
The button results in a CSV file, just like the CSV file described in the previous section. The only difference is that only soft- and hardware items that are in use by any of your Constituents will be placed in this file.
Export all photos
You can all the photos of your constituents. You can use this list e.g. as a backup in case Taranis is not available. The output is again a CSV-file just as with the empty photo. The only difference is that an extra column (“Constituent”) is added to the list.
After installation of Taranis only the ‘admin’ user is defined. To add a new user or edit the properties of an existing user, open the users’ details window. It will show some basic properties of the user (figure 5-30). You can specify the full name, email address. and email name of this user.
The “Role” tab allows the administrator to specify which roles the users will have.
Figure: User configuration
By default only the role ‘Taranis Administrator’ is available, which allows full access to the configuration. You may link multiple roles to a single user; to do this, the access rights the user will receive are cumulative (the rights of all the roles combined).
The “Change password” tab allows the administrator to change the current password of the users. The “Actions” tab gives you an overview of the last actions by this user.
Taranis supports a granular authorization framework in which users can get access to the different features of Taranis. This authorization framework makes use of “roles”, “entitlements”, and “particularizations”. An entitlement defines the authorization a user can have on a very specific component of Taranis, e.g. authorizations to access the “Assess”-part of Taranis.
A role is used to group a list of entitlements and to specify the exact rights on this entitlement. Possible rights on an entitlement are “Read” (R), “Write” (W) and “Execute (X). When a user has for example only Read-access to items he or she can read the items collected but cannot change the status of these items.
| admin_generic | Defines access to generic administration features |
| analysis | Analyses |
| configuration_generic | Item categories, collector logs, ID patterns |
| configuration_parser | Parser definitions |
| configuration_strips | <currently not in use> |
| Constituent_groups | Constituent groups, soft-/hardware linked to Constituent groups |
| Constituent_individuals | Constituent individuals, Constituent roles |
| cve | CVE Descriptions |
| damage_description | Damage descriptions |
| entitlements | <currently not in use> |
| dossiers | The dossier functionality |
| generic | Basic access (required for every user) |
| item_analysis | Items from assessment to analyze, bulk analysis, multiple analyses |
| items | Items |
| membership | <currently not in use> |
| photo_import | Photo management features under Configuration |
| publication | Publications, soft-/hardware list, publishing, calling lists |
| publication_template | Publication templates |
| publication_type | <currently not in use> |
| report | Report functionality |
| rest_level_1-4 | Access to the REST API |
| role_right | Roles, role rights |
| roles | Roles, role rights |
| soft_hard_usage | <currently not in use> |
| software_hardware | Soft-/hardware types, soft-/hardware list |
| sources_errors | <currently not in use> |
| sources_items | Sources, strips |
| sources_stats | Statistics |
| tools | Tools |
| user_action | User actions |
| user_role | User roles, users |
| users | Users |
The ‘Rights’ tab for a role shows all the entitlements along with three checkboxes (R, W, X) and sometimes a particularization.
Figure: Role rights
Some entitlements support a particularization. These particularizations enable the administrator to further limit the access of the user to certain subsets of the entitlement. The example shows that the role has read-, write- and execute-access to analyses, but only for analyses with the statuses ‘Done’, ‘Eow’, ‘Eow Done’ and ‘Pending’. This means that the user does not have access to analyses with another status than those.
Publication templates ease the process of advisory creation. You can create templates for texts that you often use in your publications. Taranis comes with several publication templates: ‘Advisory (email)’, ‘Advisory (update)’, ‘Advisory (forward), ‘Advisory (forward update)’, ‘End-of-Shift (email)’, and ‘End-of-Week (email)’. You can change these templates to adapt the standard NCSC-NL products for your own use.
The strength of templates lies in the fact that you can easily create publications thereby avoiding errors and using uniform texts. To enable flexibility in your templates, you can use variables in your texts.
When describing vulnerabilities and solutions, for example, you will regularly see updates from the same vendor. The texts you use to describe these solutions are often the same. To ease this process you decide to create a template to describe an update from Ubuntu. The text you use for Ubuntu-updates is something like this:
Ubuntu released updates for Ubuntu 12.04 LTS to resolve this issue. You can install these updates by using 'apt-get update' and 'apt-get upgrade'. More information about the vulnerability can be found here: http://www.ubuntu.com/usn/USN-1439-1
You can create a template for the text shown above by choosing “Publication Templates” from the main configuration screen and then clicking ???. The window that will open, allows you to specify some general properties of the template you’re about to create.
Figure: New publication template
Make sure the title properly describes the contents of your template, as this is the name you will see when loading templates into your advisory or other publications. Also, specify in which product you want to normally use your template.
The ‘Template’-tab contains the actual template, formatted as XML. Taranis fills in the following XML in this tab:
<publication>
<template>
</template>
<fields>
</fields>
</publication>The template-text must be placed in the <template> container. Variables to be used in the text must be placed in the <fields> container.
If we use the example text for Ubuntu and replace the dynamic parts with variables, the text could look something like this:
Ubuntu released updates for Ubuntu _fld_ubuntuversion_ to resolve this issue. You can install these updates by using 'apt-get update' and 'apt-get upgrade'. More information about the vulnerability can be found here: http://www.ubuntu.com/usn/USN-_fld_ID_
Variables in the text must be enclosed by underscores ('_'). The first variable in the text is the Ubuntu versions that are updated which we will call variable _fld_ubuntuversion_. The second variable is the ID of the Ubuntu advisory-ID which we will call variable _fld_ID_.
Now that we defined these two variables, we will have to tell Taranis what kind of variables these are. Taranis supports the following input types for variables:
- Text area;
- Textbox;
- Dropdown list;
- Radio buttons;
- Checkboxes.
<fields> container. For the Ubuntu version we want to show a list of supported versions that can be checked by the user:
<fld_ubuntuversion desc="Ubuntu version(s)"> multiple:10.04 LTS:11.10:12.04 LTS </fld_ubuntuversion>
Each variable must be represented as an XML-tag. The description for the variable is stored in the desc-attribute. Between the variable tags, the user can specify the type of input field (textarea, text, dropdown, radio or multiple). Properties for the input field are placed behind the type-indicator, divided by colons.
Example Result:
-
textarea:10:20Shows a text area with 10 columns and 20 rows. -
text:10Shows a textbox with size 10. -
dropdown:a:b:cShows a dropdown list with values ‘a’, ‘b’ and ‘c’. -
radio:a:b:cShows three radio buttons with values ‘a’, ‘b’ and ‘c’. -
multiple:a:b:cShows three checkboxes with values ‘a’, ‘b’ and ‘c’.
<publication>
<template>
Ubuntu released updates for Ubuntu _fld_ubuntuversion_ to resolve this issue. You can install these updates by using 'apt-get update' and 'apt-get upgrade'. More information about the vulnerability can be found here:
http://www.ubuntu.com/usn/USN-_fld_ID_
</template>
<fields>
<fld_ubuntuversion desc="Ubuntu version(s)">
multiple:8.04 LTS:10.04 LTS:11.10:12.04 LTS:12.10
</fld_ubuntuversion>
<fld_ID desc="Ubuntu-ID (USN-XXX-X):">text:170</fld_id>
</fields>
</publication>After you’ve entered the template, press the button to find out if your XML is syntactically correct. If validation of the template was successful, you can save it and use it in your publications. The figure below shows how the Ubuntu-template can be used in an advisory.
Figure: Using templates
To standardize the damage descriptions for advisories, Taranis enables you to administer a standard list of damage descriptions to include in your advisory. Open the list of damage descriptions through “Damage description” on the “Publication configuration” pane.
Examples of damage description that NCSC-NL uses in its advisories are ‘Remote code execution’ and ‘Denial of Service’. All the damage descriptions you add to this list, will automatically be loaded into the advisory.
Figure: a list of possible damage descriptions loaded in an advisory
Taranis keeps a list of all soft- and hardware. This list is used to indicate vulnerable software in an advisory. By linking Constituent groups to soft- and hardware, it is possible to automatically send an advisory only to Constituent groups that use that vulnerable soft- or hardware. You can manually add new items to the list or use the CPE list maintained by MITRE.
Below an example of the soft-/hardware list. For each piece of soft-/hardware, Taranis shows an icon that indicates the use of the soft-/hardware within the constituency. This can help in deciding to write an advisory or skip it because the soft-/hardware is not in use.
Figure: The soft-/hardware list
When a particular piece of soft-/hardware is in use (see the ‘in use indicator’), you can move your mouse pointer over the indicator to see which organizations use this soft-/hardware. An administrator can open the details of the soft-/hardware by clicking on the ???-icon next to it.
You can add new hard- or software to the list by clicking on the button at the top of the page. This will open up a pop-up like:
Figure: Add new hard- or software
Specify the name of the producer (vendor), the name of the product, and optionally a version number of the soft- or hardware. CPE ID is only used with soft- and hardware imported from the CPE-list. The type indicates what you want to add to the list:
- Hardware;
- Operating System; or
- Software.
Keeping the list of soft- and hardware up-to-date can be a daunting task. To ease the maintenance of this list, Taranis supports the use of the Common Platform Enumeration (CPE) list maintained by MITRE. According to MITRE:
“CPE is a structured naming scheme for information technology systems, platforms, and packages. Based upon the generic syntax for Uniform Resource Identifiers (URI), CPE includes a formal name format, a language for describing complex platforms, a method for checking names against a system, and a description format for binding text and tests to a name.”
You can import the latest CPE-dictionary by clicking on the button on top of the screen. Clicking on this button will open up this screen:
Figure: Import CPE dictionary
MITRE offers the CPE dictionary in the form of an XML file that is regularly updated. You can import this file directly by specifying the URL or you can enter a full path to the file on the server.
The CPE dictionary contains a lot of items. You can limit the number of items imported in Taranis by selecting the ‘Don’t import items with version’ option. Whether this is suitable for your situation mainly depends on the way your constituents specify the hard- and software they use. If they just specify the products without version numbers, you can use this filter without problems.
Click on ‘load file’ to start the import. This process is RAM intensive, so make sure you comply with the minimum system requirements.
Figure: Download and processing
After Taranis successfully processed the dictionary, it will show:
Figure: CPE-import
Taranis presents you a list of all new and changed items from the CPE-list. All new items are flagged with ???.
The figure below shows an example of a CPE-item where the product name name in Taranis (‘Integrated Runtime’) is different from the product name in the CPE (‘Integrated Runtime (AIR)’).
Figure: Changed CPE-item
It is up to you to decide how you want to process the information from the CPE. The easiest way to make your choice is by clicking on the words on the bottom of the page:
Figure: Actions on CPE-items
By clicking on the words you can define the actions to be taken on which pieces of information:
- What you want to do: import or discard.
- Which items it concerns: all new, all changed or all selected.
After you finished the complete list, Taranis may ask you if you want to import items that are only listed with a version number. This will happen if you selected the ‘Don’t import items with version’ option at the start of the import. The reason Taranis asks you this question, is because there are apparently products listed in the CPE that are only listed with a version number and not without. If you would ignore these items, you would end up with an incomplete list of hard- and software. What Taranis can do in this situation is to create a new soft- or hardware item based on the information in the CPE but without a version-number. Because this item is not listed in the CPE, it will not receive a CPE-ID. If you want to do this, click on the ???-button. If not, choose the ???-button.
Figure: Remaining CPE-items after the import
All the records in the soft-/hardware list are linked to a soft-/hardware type. Taranis needs to know what type a specific piece of hard- or software is, in order to be able to distinguish operating systems from applications running on top of that. This is especially important for advisories as these publications have different sections for the selection of vulnerable operating systems and vulnerable applications.
Based on the CPE-list, Taranis distinguishes the following software and hardware types by default:
- Application;
- Hardware; or
- Operating System.
Figure: Creating a custom soft-/hardware type
The “Other configuration” pane is used to configure settings that do not fit under one of the other categories. Currently, the tools configuration, access tokens, CVE Descriptions and CVE Templates are part of this pane.
The tools configuration pane enables you to administer the tools visible under de “Tools” menu on the frontpage.
Plugging in existing tools
You can plug different tools into Taranis. By default, Taranis comes with four different tools: ‘WHOIS’, ‘Phishing Checker’, ‘Big Screen’ and ‘Feed Digest’. Every tool you define has three properties:
- Name;
- Webscript; and
- Back-end script.
The figure below shows the configuration of the phishing checker that has both a front-end and back-end: the front-end shows the status of all phishing websites, the back-end checks the current status of those websites.
Figure: tool configuration
Create your own tool
You can easily add your own tools to Taranis. All you need is some creativity, some Perl knowledge, and the information provided in this paragraph. As an example we create a tool called the “Hello World” tool which will only display the message “Hello World”. In order to create this tool, you first create this very simplistic helloworld.pl script:
#!/usr/bin/perl
my @EXPORT_OK = qw(displayHelloWorld);
sub helloworld_export {
return @EXPOERT_OK;
}
sub displayHelloWorld {
my $htmlContent = "<h1>Hello world!</h1>";
return { content => $htmlContent };
}
1;
The following things are important in creating this script:
- It must contain an
@EXPORT_OKarray defining the subs that you want to be accessible through the web interface. - It must contain an
_export-sub that returns this@EXPORT_OKarray. The name of this sub corresponds with your tool name followed by the_exportstring (e.g.helloworld_export). - The subs specified in the
@EXPORT_OKarray must be part of the same file.
<entitlement id="helloworld">
<menuitem>1</menuitem>
<use_entitlement>tools</use_entitlement>
</entitlement>Make sure that the ID of your entitlement matches the name of your script (without the .pl extension).
Place your helloworld.pl in a subdirectory of the mod_tools-directory of Taranis. The directory name and the script name should correspond. In this case you create the directory scripts/mod_tools/helloworld/ and copy the script helloworld.pl to this newly created directory.
Your tool is now almost ready to use. Make sure that the permissions and ownership of your new tool are set correctly. On Ubuntu you should e.g. issue the following commands:
cd /opt/Taranis/mod_tools/ chown -R apache: ./helloworld/ chmod -R 755 ./helloworld/
Now add your tool definition by following the steps outlined in the previous paragraph. Use the settings as shown below:
Figure: Tool details
The last step is to restart or reload your Apache daemon and login to Taranis for all changes to take effect. If all went well, you should now see your tool listed in the Tools menu. Of course, the example shown is very simple but it should help you get up and running with the tools functionality. You could check the other tools scripts included with Taranis to see what other functionalities are offered by this functionality. You can make use of all core Taranis components which should enable you to easily integrate your extension into Taranis!
Access Tokens are used to grant users access to the REST API of Taranis. Use the ‘Add new tokens’ to add them. Select a user and an expire time.
CVE descriptions can be used to translate or describe a CVE once and then use it in multiple advisories. The original descriptions are provided by MITRE. The URL from which these descriptions are downloaded can be managed with the ???-button. This will show the page shown here:
Figure: Manage CVE download files
Use the add URL link to add additional URL’s. The descriptions are downloaded and processed with taranis cve descriptions.
CVE descriptions can be very similar for vulnerabilities that are related to each other. In such a case you can use a CVE Template. A new template can be added with the ???-button.
images/taranis-logo-medium.png ©NCSC-NL, License: EUPL-1.2