List of docker images and services
ACUBETotal
| Type | Default Location |
|---|---|
| env-file | /etc/default/acubetotal |
Docker images
- acubetotal-authorization:main
- acubetotal-frontend:main
- acubetotal-pipeline:main
- acubetotal-prisma:main
- acubetotal-service-capa:main
- acubetotal-service-cape_to_stix:main
- acubetotal-service-detect_it_easy:main
- acubetotal-service-elfparser:main
- acubetotal-service-floss:main
- acubetotal-service-olevba:main
- acubetotal-service-pe_info:main
- acubetotal-service-peepdf:main
- postgres:16
- elasticsearch:8.13.0
systemd units
- acubetotal-auth.service
- acubetotal-database.service
- acubetotal-elasticsearch.service
- acubetotal-frontend.service
- acubetotal-pipeline.service
- acubetotal-prisma_migrate.service
- acubetotal-prisma_studio.service
- acubetotal-rabbitmq.service
- acubetotal-service-capa.service
- acubetotal-service-cape_to_stix.service
- acubetotal-service-detect_it_easy.service
- acubetotal-service-elfparser.service
- acubetotal-service-floss.service
- acubetotal-service-olevba.service
- acubetotal-service-pe_info.service
- acubetotal-service-peepdf.service
OpenCTI
info
The current OpenCTI version used by ACUBETotal is 5.11.12
| Type | Default Location |
|---|---|
| Directory | /opt/OpenCTI |
| env-file | /opt/OpenCTI/.env |
| docker-compose | /opt/OpenCTI/docker-compose.yml |
Docker images
- opencti/platform:5.11.12
- opencti/worker:5.11.12
- opencti/connector-history:5.11.12
- opencti/connector-export-file-txt:5.11.12
- opencti/connector-export-file-csv:5.11.12
- opencti/connector-export-file-stix:5.11.12
- opencti/connector-import-file-stix:5.11.12
- opencti/connector-import-document:5.11.12
- redis:7.0.11
- docker.elastic.co/elasticsearch/elasticsearch:8.8.1
- minio/minio:RELEASE.2023-05-18T00-05-36Z
- rabbitmq:3.12-management
systemd units
- opencti.service
CAPEv2 Sandbox
| Type | Default Location |
|---|---|
| Directory | /opt/CAPEv2 |
| env-file | /opt/OpenCTI/.env |
| docker-compose | /opt/OpenCTI/docker-compose.yml |
Docker images
- inetsim-docker:main
- postgres:15
- mongo:6.0.5
note
Currently, postgres and MongoDB are installed and run on the host instead of in docker containers.
systemd units
info
All services are run by the cape user, other than cape-rooter.service and inetsim.service, which is run as root
- cape.service
- cape-web.service
- cape-rooter.service
- cape-processor.service
- inetsim.service
Correlation
Work in Progress