an introduction to rtir

61
RT and RT for Incident Response

Upload: jesse-vincent

Post on 17-May-2015

1.708 views

Category:

Technology


3 download

DESCRIPTION

An introduction to RTIR as presented to a number of Mexican universities just before the UNAM.mx Congreso de Seguridad en Cómputo

TRANSCRIPT

Page 1: An introduction to RTIR

RT and RT forIncident Response

Page 2: An introduction to RTIR

Carlos Fuentes

Page 3: An introduction to RTIR

RedIRIS

Page 4: An introduction to RTIR

Jesse Vincent

Page 5: An introduction to RTIR

Best Practical

Page 6: An introduction to RTIR

I’m a software vendor

Page 7: An introduction to RTIR

This talk is dangerously close to a sales pitch

Page 8: An introduction to RTIR

I’m not a sales guy

Page 9: An introduction to RTIR

All the software we make is open source

Page 10: An introduction to RTIR

You can use it for free, forever

Page 11: An introduction to RTIR

We’d be happy if you use it for free

Page 12: An introduction to RTIR

(Yes, we do sell support, training,

Page 13: An introduction to RTIR

What is RT?

Page 14: An introduction to RTIR

Who uses RT?

Page 15: An introduction to RTIR

RT Features

Page 16: An introduction to RTIR

Tickets

Page 17: An introduction to RTIR

Queues

Page 18: An introduction to RTIR

Custom Fields

Page 19: An introduction to RTIR

Scrips

Page 20: An introduction to RTIR

Access Control

Page 21: An introduction to RTIR

RTFM

Page 22: An introduction to RTIR

Ticket Aging

Page 23: An introduction to RTIR

Ticket Locking

Page 24: An introduction to RTIR

Email Gateway

Page 25: An introduction to RTIR

PGP Support

Page 26: An introduction to RTIR

Charts and Reports

Page 27: An introduction to RTIR

Dashboards

Page 28: An introduction to RTIR

Feeds

Page 29: An introduction to RTIR

Themability

Page 30: An introduction to RTIR

Web API

Page 31: An introduction to RTIR

Perl API

Page 32: An introduction to RTIR

CLI Tool

Page 33: An introduction to RTIR

Customizability

Page 34: An introduction to RTIR

Internationalization

Page 35: An introduction to RTIR

RT Workflow

Page 36: An introduction to RTIR

What can you use RT for?

Page 37: An introduction to RTIR

Where to get RT

• http://bestpractical.com/rt

Page 38: An introduction to RTIR

What is RTIR?

Page 39: An introduction to RTIR

Who uses RTIR?

Page 40: An introduction to RTIR

RTIR Features

Page 41: An introduction to RTIR

RTIR Terms

Page 42: An introduction to RTIR

Incident Reports

Page 43: An introduction to RTIR

Incidents

Page 44: An introduction to RTIR

Investigations

Page 45: An introduction to RTIR

Blocks

Page 46: An introduction to RTIR

MakeClicky

Page 47: An introduction to RTIR

Lookup Tool

Page 48: An introduction to RTIR

RTIR Automated Rules

• (scrips)

Page 49: An introduction to RTIR

Using RTIR and RT together

Page 50: An introduction to RTIR

RTIR Homepage

Page 51: An introduction to RTIR

Linking tickets

Page 52: An introduction to RTIR

The Duty Team

Page 53: An introduction to RTIR

RTIR Workflow

Page 54: An introduction to RTIR

RTIR History

Page 55: An introduction to RTIR

RTIR 1.0

• Sponsored by JANET-CERT

• Built on RT 3.0

•$DATE?$

Page 56: An introduction to RTIR

RTIR 2

• Sponsored by TERENA RTIR WG

• Initial vision by JANET-CERT

• Design collaboration between TERENA and Best Practical

• Built on RT 3.8

Page 57: An introduction to RTIR

RTIR 2.0 New Features• PGP Integration

• Ticket Locking

• Ticket Aging

• Database Pruning

• RTFM Integration

• IP Address Range Fields

• Improved Customization

• Improved Reporting

• Improved Testing

• Improved Performance

• Improved UI

Page 58: An introduction to RTIR

System Requirements

• Unix/Linux/FreeBSD/MacOS X/Solaris/etc

• MySQL, PostgreSQL or Oracle

• mod_perl or FastCGI (Apache)

Page 59: An introduction to RTIR

Getting RTIR

• http://bestpractical.com/rtir

Page 60: An introduction to RTIR

RT & RTIR Community

• http://wiki.bestpractical.com

[email protected]

[email protected]

[email protected]

[email protected]

Page 61: An introduction to RTIR

Muchas gracias!

• Jesse Vincent

[email protected]

• +1 617 812 0745

• http://bestpractical.com/rtir