The files in this repository are used to create a Docker container running a MISP ("Malware Information Sharing Platform") instance.
I rewrote the Docker file to split the components in multiple containers (which is more in the philosophy of Docker).
The MISP container needs at least a MySQL container to store the data. By default it listen to port 80. I highly recommend to serve it behind a NGinx or Apache reverse proxy.
The build is based on Ubuntu and will install all the required components. The following configuration steps are performed automatically:
- Reconfiguration of the base URL in
config.php
- Generation of a new salt in
config.php
- Generation of a self-signed certificate
- Optimization of the PHP environment (php.ini) to match the MISP recommended values
- Creation of the MySQL database
- Generation of the admin PGP key
Included is an optional Docker Compose file 'docker-compose-nginx.yml' to spin up a reverse proxy to sit in front of MISP.
- add your ".crt" and ".key" files to the ./misp-proxy/ssl folder If not implementing SSL (not recommended) then simply comment out the appropriate lines in the "./misp-proxy/default.conf" file.
- Update "server_name" in default.conf file (will implement ENVIRONMENT VARIABLE in the future)
# git clone https://github.com/MISP/misp-docker
# cd misp-docker
docker build -t misp .
Edit the docker-compose.yml and change the following environment variables:
- MYSQL_ROOT_PASSWORD
- MYSQL_MISP_PASSWORD
- MISP_ADMIN_PASSPHRASE
- Changed the volumes to match your local filesystem
# docker-compose build
or
# docker-compose -f docker-compose-nginx.yml build
# docker-compose up
or
# docker-compose -f docker-compose-nginx.yml up