RT and RT for Incident Response



Similar documents
RT and RT for Incident Response

Request Tracker for Incident Response (RTIR)

IT Support Tracking with Request Tracker (RT)

RT for Incident Response (RTIR)

Request Tracker 3.8. Stefan Hornburg. Nordic Perl Workshop Oslo, 17 th April 2009

RTIR incident handling work-flow

Simplifying Your IT Helpdesk with Request Tracker

Network Management & Monitoring Ticketing Systems with RT

Ticketing Systems with RT

Request Tracker User s Guide. : Describes the User Interface and usage of Request Tracker V3.

How To Create A Ticketing System With Rt.Org

Total Cloud Control with Oracle Enterprise Manager 12c. Kevin Patterson, Principal Sales Consultant, Enterprise Manager Oracle

Jitterbit Technical Overview : Microsoft Dynamics CRM

Enabling ITIL Best Practices Through Oracle Enterprise Manager, Session # Ana Mccollum Enterprise Management, Product Management

Ticketing Systems and Documentation

Designing and Developing an Application for Incident Response Teams

Sugar Professional. Approvals Competitor tracking Territory management Third-party sales methodologies

Sugar Professional. Approvals Competitor tracking Territory management Third-party sales methodologies

Organise Your Business

The open source enterprise solution pre-configured for the IT Asset Management

use ready 2 The open source enterprise solution pre-configured for the IT Asset Management Tecnoteca Srl

everything HelpDesk [Ease of Use] [100% Web Help Desk] [Business Process Automation] [World Class Customer Service]

Jitterbit Technical Overview : Salesforce

Jitterbit Technical Overview : Microsoft Dynamics AX

Digital Marketing Manager, Marketing Manager, Agency Owner. Bachelors in Marketing, Advertising, Communications, or equivalent experience

Role-Based Solution Description

Request Tracker/RTx::AssetTracker at DigitalGlobe

Optimally Manage the Data Center Using Systems Management Tools from Cisco and Microsoft

PNMsoft Sequence Ticketing Solution (PSTS)

Installation, Configuration and Administration Guide

WEB HELP DESK GETTING STARTED GUIDE

Editions Comparison Chart

Organise Your Business

ScienceLogic vs. Open Source IT Monitoring

Ai.CRM. Extending SAP Consume-to-Cash Functionalities Product Overview

Service Asset & Configuration Management PinkVERIFY

quality of service Screenshots

Enterprise IT is complex. Today, IT infrastructure spans the physical, the virtual and applications, and crosses public, private and hybrid clouds.

Kaseya Traverse. Kaseya Product Brief. Predictive SLA Management and Monitoring. Kaseya Traverse. Service Containers and Views

Agile Development with Jazz and Rational Team Concert

Product Information. Sugar vs Zoho. Features Comparison

2012 Nolio Ltd. All rights reserved

Vistara Lifecycle Management

MARION COUNTY Information Technology. REQUEST FOR INFORMATION Integrated IT Help Desk Client Management Software Suite

Information Technology Services Classification Level Range C Reports to. Manager ITS Infrastructure Effective Date June 29 th, 2015 Position Summary

How To Create A Help Desk For A System Center System Manager

Adam Rauch Partner, LabKey Software Extending LabKey Server Part 1: Retrieving and Presenting Data

ManageEngine ServiceDesk Plus - MSP Training Agenda

The Mandate for Lights-Out IT Management

HEAT DSM Release Overview. Andreas Fuchs Product Management November 16th, 2015

Management Packs for Database

Minimizing ITSM cost of entry: HP Service Anywhere

Migration Quick Reference Guide for Administrators

1.1 SERVICE DESCRIPTION

WHITEPAPER Map, Monitor, and Manage Distributed Applications in System Center 2012

OTRS: Issue Management System Meets Workflow of Security Team Pavel Kácha, 2007 CESNET, z. s. p. o.

Take Control of Your Wireless Network Operations

Information Risk Management. Alvin Ow Director, Technology Consulting Asia Pacific & Japan RSA, The Security Division of EMC

Moving beyond Virtualization as you make your Cloud journey. David Angradi

State of Tennessee Sourcing Event #9160 ServiceNow Preliminary Statement of Work (SOW)

Implementing Project Server 2010

5 CMDB GOOD PRACTICES

Customer Happiness, refreshingly easy

Oracle Reference Architecture and Oracle Cloud

SES / CIF. Internet2 Combined Industry and Research Constituency Meeting April 24, 2012

The Need for Intelligent Network Security: Adapting IPS for today s Threats

Novo Facility Manager Supporting YOU as you support your Team

Performing Advanced Incident Response Interactive Exercise

BMC Remedy OnDemand. Product Overview

Asset management guidelines

Managing your Red Hat Enterprise Linux guests with RHN Satellite

Achieve Service Excellence with VivaDesk

tibbr Now, the Information Finds You.

The Definitive Guide. Monitoring the Data Center, Virtual Environments, and the Cloud. Don Jones

W H IT E P A P E R. Salesforce CRM Security Audit Guide

Predictive Analytics Client

Meister Going Beyond Maven

RBackup Server Installation and Setup Instructions and Worksheet. Read and comply with Installation Prerequisites (In this document)

1 Product. Open Text is the leading fax server vendor in the world. *

Tuskar UI Documentation

Simple Service Modeling FAQs TrueSight Operations Management (BPPM) versions 9.5 and /31/2014

Data Backup and Restore (DBR) Overview Detailed Description Pricing... 5 SLAs... 5 Service Matrix Service Description

AWS Service Catalog. User Guide

Why Test ITSM Applications for Performance? Webinar

Going ITIL with Countersoft Gemini

CRM for Customer Service and Support

ActiveVOS Server Architecture. March 2009

Typo3_tridion. SDL Tridion R5 3/21/2008

Automated resolving of security incidents as a key mechanism to fight massive infections of malicious software

Second CRM Startup Pack

Introduction to Endpoint Security

None (yet) 3.8% 47. More than % 480. Web Designer 18.4% 222. Web Developer 94.6% 1,141. System Administrator 36.3% 438

The SIEM Evaluator s Guide

Junos WebApp Secure (formerly Mykonos)

Cisco Process Orchestrator Adapter for Cisco UCS Manager: Automate Enterprise IT Workflows

! Resident of Kauai, Hawaii

Express Virtual Meetings

CA Nimsoft Service Desk

What s new in AM 9.30 Accelerating business outcomes

A Guide To Evaluating a Bug Tracking System

Transcription:

RT and RT for Incident Response

I represent a software vendor

We sell support, training, consulting and customization for RT, RTIR and RTFM

This talk could be dangerously close to a sales pitch.

I m not a sales guy

All the software we make is open source.

We helped create RTIR to let CERT teams be more effective.

I want you to use RTIR for free - forever.

I will be happy if you use it for free.

(Now do you believe that I m not a sales guy?)

About RT

RT is a Ticketing System

RT helps keep you organized.

Every conversation gets a number, a status and an owner.

RT helps keep your customers happy.

RT sends an autoreply and ticket number when they report a problem.

RT helps keep your team from going crazy.

You know what s been done, and when.

RT helps you show your bosses how hard you work.

It s easy to run reports on all kinds of metrics.

RT builds an ad-hoc knowledge base.

(With RTFM, you can build an explicit Knowledge Base)

Some RT history... Created in 1996 First public release in 1997 2.0 released in 1999 Best Practical formed in 2001 RTIR Created in 2003 RTIR WG Started in 2005 RTIR 2.4 Released 2008 (Last week!)

What is RT useful for? Issue Tracking Trouble Ticketing Workflow Helpdesk Customer Service Process Management Bug Tracking

RT Homepage

Ticket Details

Ticket History

Ticket Update

Ticket History

RT Core Concepts Tickets Queues Custom Fields Scrips Access Control Email Gateway Internationalization

Tickets Track issues Have unique id #s Keep a history of correspondence Have one owner (And a bunch of other metadata)

Queues High-level grouping of tickets Each can have its own Access Control Business Logic (Scrips) Custom Fields

Custom Fields Track your own ticket metadata Freeform (optional validation) Select (one or many) Text block Upload files or images Custom data sources Per-field access control

Scrips Custom business logic (Also how RT sends mail) Each is built from Condition Action Template

Access Control User, Group or Role based Global and Per-queue rights

Email Gateway RT was first made to replace a mailing list RT is designed for email interaction (and web. and command line) RT mediates and tracks all discussions

Internationalization Fully native UTF8 internally Speaks 22 languages Handles inbound and outbound email encoding Contribute at https://translations.launchpad.net/rt/

More RT Features Charts and Reports Dashboards Self-service interface Feeds RTFM PGP Support Themability Ticket Aging Ticket Locking Web API Perl API CLI tools Customizability The Community

Where to get RT http://bestpractical.com/rt

Questions about RT? (Next up: RTIR)

RTIR RT for Incident Response

What is RTIR? Ticketing System RT for Incident Response Designed for CERT/CSIRT Teams Designed for a CERT team - JANET-CERT Generalized for a standard process

Differences from RT RTIR is RT...with more features, a custom interface and special configuration

Designed for CERT/CSIRT Teams Metadata Workflows Views Plugins

We designed RTIR to help you get your job done.

RTIR keeps track of incidents.

RTIR keeps track of correspondence.

RTIR keeps an uneditable history.

RTIR makes incident research easier.

RTIR tracks your SLA commitments.

RTIR integrates with your other systems.

RTIR takes care of the boring parts of Incident Response.

The RTIR Workflow

RTIR Homepage

RTIR is built around Incidents Incidents tie everything together One Incident for many Incident Reports many Investigations many Blocks

RTIR Relationships

It usually starts with an Incident Report Conversations with Customers Something bad happened! Please help me!

Incident Report

Incident Report

Create an IR

Create an IR #2

IR Details

IR History

Incident Report Reply

Incident Report History

Once reported, the team tracks an Incident Track what actually happened Private / Internal Tie everything together

Incident Lifecycle

Create an Incident

Incident Details

Incident Details #2

Incident History

Incident! Investigation

The team starts an Investigation Internal Research and Discovery Conversations with external partners Law Enforcement Network Providers Experts

Investigation Lifecycle

Investigation Workflows

Launch Investigation

Launch Investigation

Investigation Details

Investigation History

Sometimes the easiest answer is just a Block (Optional Feature) Tied to an Incident Records of network blockades Could autoupdate firewalls

Create a Block

Data Detectors

Automatic IP Detection

Data Detectors

Research Tools

RTIR History

RTIR 1.0 Sponsored by JANET-CERT Replaced a homebuilt Remedy system Built on RT 3.0 2003

RTIR 1.0 Features Clickable Data Detectors IP/Domain/Address Lookup Tool RTIR Automated Rules SLA Monitoring Business-Hours Logic

RTIR 2 Sponsored by TERENA RTIR WG Initial vision by JANET-CERT Design collaboration between RTIR WG and Best Practical Built on RT 3.8 RTIR 2.4 released September 2008

RTIR WG Members JANET CSIRT/UKERNA (Chair of project) IRIS-CERT/RedIRIS (Technical contact) CERT POLSKA ACOnet-CERT LITNET CERT SUNet CERT SWITCH-CERT CERT.PT GOVCERT.NL

RTIR 2.4 New Features PGP Integration Ticket Locking Ticket Aging Database Pruning Message Forwarding Bulk Actions Quick Actions Per-User Timezones RTFM Integration IP Address Range Fields

RTIR 2.4 New Features Improved Automation Improved Searching Improved Customization Improved Reporting Improved UI More flexible workflow More user preferences Easier Integration Improved Testing Improved Performance

Using RTIR

Cost of RTIR: $0

Cost of required software: $0

Cost of required hardware: $0?

Operating System Unix/Linux/FreeBSD/MacOS X/Solaris/etc (We don t do Windows)

Database MySQL 4.1 or 5.0 PostgreSQL 8.x Oracle 9x or 10.x SQLite (for testing)

Web Server Apache mod_perl or FastCGI lightttpd FastCGI Standalone pure-perl server

Getting RTIR http://bestpractical.com/rtir

RT & RTIR Community http://wiki.bestpractical.com - http://rtir.org rtir-subscribe@lists.bestpractical.com rt-es-subscribe@lists.bestpractical.com rt-users-subscribe@lists.bestpractical.com rt-devel-subscribe@lists.bestpractical.com

Aim Institution - IP correlation Correlate automatically the IPs of the IRs, Invs and Blocks with its institutions Allow us an easiest way to address an investigation Statistic by institution What institution got more complaints at the end of the year! When I say institution, it could be department

Requirements and Requirements Installation Main one!!! database which associates every institution or department with its IP allocation space LDAP, MySQL,, even a whois server Modify the Customer CustomField of IR and Invs queues to support external values You have to create your own library Has to have three functions: SourceDescription ExternalValues GetInstitutionByIP

Requirements and Install Download It will be in http://www.rtir.org, Extensions area Condition OnIPCreate Condition OnIPDelete