Installation Steps
Last updated
Last updated
First, you need to clone the repository:
Move to the directory and execute the installation script:
To install the main T-Guard components, you need to install from step 1 to step 6 in Figure 1.
In the step 1, during update system and install prerequisites, if you encounter a popup, just click Ok.
In the step 2, after Docker installation, to make sure the Docker service is running well, you can execute the following command:
The green text indicates Docker is running well as illustrated in Figrue 2.
We can proceed to the next step, installing Wazuh, which serves as SIEM. This step will take quite a long time, depending on the internet connection speed.
After the Wazuh installation success, we deploy the Wazuh Agent in the machine. Insert your machine IP Address and Wazuh Agent. In example, as illustrated in Figure 4.
After the process is finished, go to your browser and check your Wazuh by following this link:
You will see a warning from the browser that the certificate is invalid as illustrated in Figure 5. This is normal because we haven’t installed the signed SSL certificate, which is recommended for production. For now, just click proceed.
The first page of Wazuh should be as illustrated in Figure 6.
Log in using the credentials mentioned at the bottom of the page. After log in, you should see Figure 7.
Proceed installing Shuffle by execute step 4.
After installation process is finished, go to your browser and check your Shuffle by following this link:
http://<ip>:3001
Create administrator account and login using the credentials mentioned at the bottom of the page. After log in, you should see Figure 8.
Execute step 5.
After installation process is finished, go to your browser and check your IRIS by following this link:
https://<ip>:8443
Sign in using the credentials mentioned at the bottom of the page. After log in, you should see Figure 9.
Execute step 6.
After installation process is finished, go to your browser and check your MISP by following this link:
https://<ip>:1443
Sign in using the credentials mentioned at the bottom of the page. After log in, you should see Figure 10.
Next, we will Integrate all the module in the next page.
Service
Web Interface
Username
Password
Wazuh
https://<ip>
admin
SecretPassword
DFIR-IRIS
https://<ip>:8443
administrator
MySuperAdminPassword!
Shuffle
http://<ip>:3001
administrator
MySuperAdminPassword!
MISP
https://<ip>:1443
admin@admin.test
admin
https://<your_ip>