{"id":1979,"date":"2015-05-20T15:26:22","date_gmt":"2015-05-20T22:26:22","guid":{"rendered":"https:\/\/blog.mozilla.org\/security\/?p=1979"},"modified":"2015-08-10T15:50:54","modified_gmt":"2015-08-10T22:50:54","slug":"mozdef-the-mozilla-defense-platform-v1-9","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/","title":{"rendered":"MozDef: The Mozilla Defense Platform v1.9"},"content":{"rendered":"<p>At Mozilla we&#8217;ve been using The Mozilla Defense Platform (lovingly referred to as MozDef) for almost two years now and we are happy to <a title=\"Release History\" href=\"https:\/\/github.com\/jeffbryner\/MozDef\/releases\">release v1.9<\/a>. If you are unfamiliar, MozDef is a <a title=\"SIEM Definition\" href=\"http:\/\/en.wikipedia.org\/wiki\/Security_information_and_event_management\">Security Information and Event Management (SIEM)<\/a> overlay for <a title=\"Elastic Search\" href=\"http:\/\/elastic.co\">ElasticSearch<\/a>.<\/p>\n<p>MozDef aims to bring real-time incident response and investigation to the <strong>defensive<\/strong> tool kits of security operations groups in the same way that <a title=\"Metasploit\" href=\"http:\/\/www.metasploit.com\/\">Metasploit<\/a>, <a href=\"https:\/\/github.com\/lair-framework\/lair\">LAIR<\/a> and <a title=\"Armitage\" href=\"http:\/\/www.fastandeasyhacking.com\/\">Armitage<\/a> have revolutionized the capabilities of attackers.<\/p>\n<p>We use MozDef to ingest security events, alert us to security issues, investigate suspicious activities, handle security incidents and to visualize and categorize threat actors. The real-time capabilities allow our security personnel all over the world to work collaboratively even though we may not sit in the same room together and see changes as they occur. The integration plugins allow us to have the system automatically respond to attacks in a preplanned fashion to mitigate threats as they occur.<\/p>\n<p>We&#8217;ve been on a monthly release cycle since the <a href=\"https:\/\/github.com\/jeffbryner\/MozDef\/issues?q=milestone%3A%22Release+v1%22\">launch<\/a>, adding features and squashing bugs as we find them. You can find the <a title=\"MozDef Release Notes\" href=\"https:\/\/github.com\/jeffbryner\/MozDef\/issues?q=milestone%3A%22+Release+v1.9%22+is%3Aclosed\">release notes for this version here<\/a>.<\/p>\n<p>Notable changes include:<\/p>\n<ul>\n<li id=\"magicdomid125\" class=\"ace-line\"><span class=\"author-g-x5i9yyw077cjbsd8\">\u00a0Support for Google API logs (login\/logout\/suspicious activity for Google Drive\/Docs)<\/span><\/li>\n<li id=\"magicdomid167\" class=\"ace-line\"><span class=\"author-g-x5i9yyw077cjbsd8\">\u00a0<\/span><span class=\"author-g-x5i9yyw077cjbsd8 url\"><a title=\"Cyber Reputation System\" href=\"http:\/\/cymon.io\">http:\/\/cymon.io<\/a><\/span><span class=\"author-g-x5i9yyw077cjbsd8\"> api integration<\/span><\/li>\n<li id=\"magicdomid284\" class=\"ace-line\"><span class=\"author-g-x5i9yyw077cjbsd8\">\u00a0<a title=\"Myo Armband\" href=\"https:\/\/www.thalmic.com\/en\/myo\/\">myo armband<\/a> integration <\/span><\/li>\n<\/ul>\n<p><span class=\"author-g-x5i9yyw077cjbsd8\">Using the Myo armband in a TLS environment may require some tweaking to allow the browser to connect to the local Myo agent. <a href=\"http:\/\/mozdef.readthedocs.org\/en\/latest\/advanced_settings.html#myo-with-tls-ssl\">Here&#8217;s a quick config for proxying via nginx<\/a>. Check out <a title=\"MozDef Documentation\" href=\"http:\/\/mozdef.readthedocs.org\/en\/latest\/\">the docs for other tips.<\/a><br \/>\n<\/span><\/p>\n<p>Feel free to take it for a spin on the <a title=\"MozDef Demo site\" href=\"http:\/\/demo.mozdef.com:3000\">demo site<\/a>. You can login by creating any test email\/password combination you like. The demo site is rebuilt occasionally so don&#8217;t expect anything you put there to live for more than a couple days but feel free to test it out.<\/p>\n<p>Development for the project takes place at <a title=\"MozDef Development site\" href=\"http:\/\/mozdef.com\">mozdef.com<\/a> and report any issues using the <a title=\"MozDef Issue Tracking\" href=\"https:\/\/github.com\/jeffbryner\/MozDef\/issues\">github issue tracker<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>At Mozilla we&#8217;ve been using The Mozilla Defense Platform (lovingly referred to as MozDef) for almost two years now and we are happy to release v1.9. If you are unfamiliar, &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/\">Read more<\/a><\/p>\n","protected":false},"author":1163,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[69,610],"tags":[],"coauthors":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>MozDef: The Mozilla Defense Platform v1.9 - Mozilla Security Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeff Bryner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/\",\"url\":\"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/\",\"name\":\"MozDef: The Mozilla Defense Platform v1.9 - Mozilla Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\"},\"datePublished\":\"2015-05-20T22:26:22+00:00\",\"dateModified\":\"2015-08-10T22:50:54+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/cf33d7a7b6438e4d6e64f5092bc8c4bd\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"MozDef: The Mozilla Defense Platform v1.9\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/security\/\",\"name\":\"Mozilla Security Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/cf33d7a7b6438e4d6e64f5092bc8c4bd\",\"name\":\"Jeff Bryner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/2283326afb11e74c9e915fa99f92e3be\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/9ae98824ae5ce6f03a4475a8f6830ce1?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/9ae98824ae5ce6f03a4475a8f6830ce1?s=96&d=identicon&r=g\",\"caption\":\"Jeff Bryner\"},\"sameAs\":[\"https:\/\/mozillians.org\/en-US\/u\/jbryner\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"MozDef: The Mozilla Defense Platform v1.9 - Mozilla Security Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/","twitter_misc":{"Written by":"Jeff Bryner","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/","url":"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/","name":"MozDef: The Mozilla Defense Platform v1.9 - Mozilla Security Blog","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/security\/#website"},"datePublished":"2015-05-20T22:26:22+00:00","dateModified":"2015-08-10T22:50:54+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/cf33d7a7b6438e4d6e64f5092bc8c4bd"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/security\/2015\/05\/20\/mozdef-the-mozilla-defense-platform-v1-9\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/security\/"},{"@type":"ListItem","position":2,"name":"MozDef: The Mozilla Defense Platform v1.9"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/security\/#website","url":"https:\/\/blog.mozilla.org\/security\/","name":"Mozilla Security Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/cf33d7a7b6438e4d6e64f5092bc8c4bd","name":"Jeff Bryner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/2283326afb11e74c9e915fa99f92e3be","url":"https:\/\/secure.gravatar.com\/avatar\/9ae98824ae5ce6f03a4475a8f6830ce1?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9ae98824ae5ce6f03a4475a8f6830ce1?s=96&d=identicon&r=g","caption":"Jeff Bryner"},"sameAs":["https:\/\/mozillians.org\/en-US\/u\/jbryner\/"]}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/1979"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/users\/1163"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/comments?post=1979"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/1979\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/media?parent=1979"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/categories?post=1979"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/tags?post=1979"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/coauthors?post=1979"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}