diff --git a/README.md b/README.md index f201cf9..171e54e 100644 --- a/README.md +++ b/README.md @@ -1,3 +1,15 @@ # timesketch_misp -Python Script which serves as Analyzer in Timesketch to query MISP for more values than the default misp_analyzer.py. \ No newline at end of file +Python Script which serves as Analyzer in Timesketch to query MISP for more values than the default misp_analyzer.py. + + +has to be mounted in the timesketch docker container like: + +``` +services: + web: + # ... existing config ... + volumes: + # ... existing volumes ... + - ./misp_analyzer_persistent.py:/usr/local/lib/python3.10/dist-packages/timesketch/lib/analyzers/contrib/misp_analyzer.py:ro +``` \ No newline at end of file