2014-08-06 11:43:40 +02:00
|
|
|
[Directories]
|
2014-08-20 16:00:56 +02:00
|
|
|
bloomfilters = Blooms
|
2016-08-09 14:23:36 +02:00
|
|
|
dicofilters = Dicos
|
2014-08-19 19:07:07 +02:00
|
|
|
pastes = PASTES
|
2018-04-20 10:48:44 +02:00
|
|
|
base64 = BASE64
|
2016-07-15 09:08:38 +02:00
|
|
|
|
2014-08-20 16:00:56 +02:00
|
|
|
wordtrending_csv = var/www/static/csv/wordstrendingdata
|
|
|
|
wordsfile = files/wordfile
|
2014-08-06 11:43:40 +02:00
|
|
|
|
2016-07-15 09:08:38 +02:00
|
|
|
protocolstrending_csv = var/www/static/csv/protocolstrendingdata
|
|
|
|
protocolsfile = files/protocolsfile
|
|
|
|
|
|
|
|
tldstrending_csv = var/www/static/csv/tldstrendingdata
|
2016-07-22 09:32:13 +02:00
|
|
|
tldsfile = faup/src/data/mozilla.tlds
|
2016-07-15 09:08:38 +02:00
|
|
|
|
|
|
|
domainstrending_csv = var/www/static/csv/domainstrendingdata
|
|
|
|
|
2017-01-10 18:33:46 +01:00
|
|
|
pystemonpath = /home/pystemon/pystemon/
|
|
|
|
|
2017-01-11 11:00:36 +01:00
|
|
|
sentiment_lexicon_file = sentiment/vader_lexicon.zip/vader_lexicon/vader_lexicon.txt
|
|
|
|
|
2018-02-27 15:12:02 +01:00
|
|
|
##### Notifications ######
|
|
|
|
[Notifications]
|
|
|
|
sender = sender@example.com
|
|
|
|
sender_host = smtp.example.com
|
|
|
|
sender_port = 1337
|
2018-03-30 11:35:37 +02:00
|
|
|
|
|
|
|
# optional for using with authenticated SMTP over SSL
|
|
|
|
# sender_pw = securepassword
|
2018-02-27 15:12:02 +01:00
|
|
|
|
2016-07-15 09:10:44 +02:00
|
|
|
##### Flask #####
|
|
|
|
[Flask]
|
2016-07-15 09:08:38 +02:00
|
|
|
#Maximum number of character to display in the toolip
|
2018-02-27 16:16:57 +01:00
|
|
|
max_preview_char = 250
|
2016-07-15 09:08:38 +02:00
|
|
|
#Maximum number of character to display in the modal
|
2018-02-27 16:16:57 +01:00
|
|
|
max_preview_modal = 800
|
2016-07-15 09:08:38 +02:00
|
|
|
#Default number of header to display in trending graphs
|
|
|
|
default_display = 10
|
2016-08-09 14:23:36 +02:00
|
|
|
#Number of minutes displayed for the number of processed pastes.
|
|
|
|
minute_processed_paste = 10
|
2018-02-27 16:16:57 +01:00
|
|
|
#Maximum line length authorized to make a diff between duplicates
|
|
|
|
DiffMaxLineLength = 10000
|
|
|
|
|
|
|
|
#### Modules ####
|
|
|
|
[Categ]
|
|
|
|
#Minimum number of match between the paste and the category file
|
|
|
|
matchingThreshold=1
|
|
|
|
|
|
|
|
[Credential]
|
|
|
|
#Minimum length that a credential must have to be considered as such
|
|
|
|
minimumLengthThreshold=3
|
|
|
|
#Will be pushed as alert if the number of credentials is greater to that number
|
|
|
|
criticalNumberToAlert=8
|
|
|
|
#Will be considered as false positive if less that X matches from the top password list
|
|
|
|
minTopPassList=5
|
2017-12-11 17:28:34 +01:00
|
|
|
|
2018-05-03 16:21:33 +02:00
|
|
|
[Curve]
|
|
|
|
max_execution_time = 90
|
|
|
|
|
2018-05-02 17:07:10 +02:00
|
|
|
[Base64]
|
|
|
|
path = Base64/
|
|
|
|
max_execution_time = 60
|
|
|
|
|
2016-07-18 15:50:41 +02:00
|
|
|
[Modules_Duplicates]
|
|
|
|
#Number of month to look back
|
|
|
|
maximum_month_range = 3
|
2016-08-09 14:23:36 +02:00
|
|
|
#The value where two pastes are considerate duplicate for ssdeep.
|
|
|
|
threshold_duplicate_ssdeep = 50
|
|
|
|
#The value where two pastes are considerate duplicate for tlsh.
|
2018-05-09 13:03:46 +02:00
|
|
|
threshold_duplicate_tlsh = 52
|
2016-07-18 15:52:53 +02:00
|
|
|
#Minimum size of the paste considered
|
|
|
|
min_paste_size = 0.3
|
2016-07-18 15:50:41 +02:00
|
|
|
|
2016-12-22 10:06:35 +01:00
|
|
|
[Module_ModuleInformation]
|
|
|
|
#Threshold to deduce if a module is stuck or not, in seconds.
|
|
|
|
threshold_stucked_module=600
|
2016-07-21 14:59:52 +02:00
|
|
|
|
2016-12-23 10:31:26 +01:00
|
|
|
[Module_Mixer]
|
2018-02-27 16:16:57 +01:00
|
|
|
#Define the configuration of the mixer, possible value: 1, 2 or 3
|
|
|
|
operation_mode = 3
|
2016-12-23 10:31:26 +01:00
|
|
|
#Define the time that a paste will be considerate duplicate. in seconds (1day = 86400)
|
|
|
|
ttl_duplicate = 86400
|
|
|
|
|
2014-08-06 11:43:40 +02:00
|
|
|
##### Redis #####
|
|
|
|
[Redis_Cache]
|
|
|
|
host = localhost
|
|
|
|
port = 6379
|
|
|
|
db = 0
|
|
|
|
|
2014-12-22 16:50:25 +01:00
|
|
|
[Redis_Log]
|
|
|
|
host = localhost
|
|
|
|
port = 6380
|
|
|
|
db = 0
|
|
|
|
|
2014-08-06 11:43:40 +02:00
|
|
|
[Redis_Queues]
|
|
|
|
host = localhost
|
|
|
|
port = 6381
|
2014-09-05 10:41:00 +02:00
|
|
|
db = 0
|
2014-08-06 11:43:40 +02:00
|
|
|
|
|
|
|
[Redis_Data_Merging]
|
|
|
|
host = localhost
|
|
|
|
port = 6379
|
|
|
|
db = 1
|
|
|
|
|
2016-08-23 09:59:39 +02:00
|
|
|
[Redis_Paste_Name]
|
|
|
|
host = localhost
|
|
|
|
port = 6379
|
|
|
|
db = 2
|
|
|
|
|
2017-01-09 14:12:26 +01:00
|
|
|
[Redis_Mixer_Cache]
|
2016-12-23 10:31:26 +01:00
|
|
|
host = localhost
|
|
|
|
port = 6381
|
|
|
|
db = 1
|
|
|
|
|
2018-05-07 14:50:40 +02:00
|
|
|
##### ARDB #####
|
|
|
|
[ARDB_Curve]
|
2016-08-09 14:23:36 +02:00
|
|
|
host = localhost
|
2016-08-23 09:59:39 +02:00
|
|
|
port = 6382
|
|
|
|
db = 1
|
|
|
|
|
2018-05-07 14:50:40 +02:00
|
|
|
[ARDB_Sentiment]
|
2016-08-23 09:59:39 +02:00
|
|
|
host = localhost
|
|
|
|
port = 6382
|
|
|
|
db = 4
|
|
|
|
|
2018-05-07 14:50:40 +02:00
|
|
|
[ARDB_TermFreq]
|
2016-08-23 09:59:39 +02:00
|
|
|
host = localhost
|
|
|
|
port = 6382
|
|
|
|
db = 2
|
2016-08-09 14:23:36 +02:00
|
|
|
|
2018-05-07 14:50:40 +02:00
|
|
|
[ARDB_TermCred]
|
2017-07-18 16:57:15 +02:00
|
|
|
host = localhost
|
|
|
|
port = 6382
|
|
|
|
db = 5
|
|
|
|
|
2018-05-07 14:50:40 +02:00
|
|
|
[ARDB_DB]
|
2014-08-06 11:43:40 +02:00
|
|
|
host = localhost
|
2018-05-07 14:50:40 +02:00
|
|
|
port = 6382
|
2014-08-06 11:43:40 +02:00
|
|
|
db = 0
|
|
|
|
|
2018-05-07 14:50:40 +02:00
|
|
|
[ARDB_Trending]
|
2016-07-15 09:08:38 +02:00
|
|
|
host = localhost
|
2016-08-23 09:59:39 +02:00
|
|
|
port = 6382
|
|
|
|
db = 3
|
2016-07-15 09:08:38 +02:00
|
|
|
|
2018-05-07 14:50:40 +02:00
|
|
|
[ARDB_Hashs]
|
2014-08-06 11:43:40 +02:00
|
|
|
host = localhost
|
|
|
|
db = 1
|
|
|
|
|
2018-05-09 13:03:46 +02:00
|
|
|
[ARDB_Tags]
|
|
|
|
host = localhost
|
|
|
|
port = 6382
|
|
|
|
db = 6
|
|
|
|
|
2014-12-22 16:29:05 +01:00
|
|
|
[Url]
|
|
|
|
cc_critical = DE
|
2014-08-11 11:04:09 +02:00
|
|
|
|
2014-09-17 17:19:03 +02:00
|
|
|
[DomClassifier]
|
|
|
|
cc = DE
|
|
|
|
cc_tld = r'\.de$'
|
2018-05-02 17:07:10 +02:00
|
|
|
dns = 8.8.8.8
|
|
|
|
|
|
|
|
[Mail]
|
|
|
|
dns = 8.8.8.8
|
2014-09-17 17:19:03 +02:00
|
|
|
|
2014-08-11 11:04:09 +02:00
|
|
|
# Indexer configuration
|
|
|
|
[Indexer]
|
|
|
|
type = whoosh
|
2014-08-20 16:00:56 +02:00
|
|
|
path = indexdir
|
2017-03-15 16:36:51 +01:00
|
|
|
register = indexdir/all_index.txt
|
2017-03-15 12:14:41 +01:00
|
|
|
#size in Mb
|
|
|
|
index_max_size = 2000
|
2014-08-29 19:37:56 +02:00
|
|
|
|
2017-11-23 07:13:44 +01:00
|
|
|
[ailleakObject]
|
|
|
|
maxDuplicateToPushToMISP=10
|
|
|
|
|
2014-08-29 19:37:56 +02:00
|
|
|
###############################################################################
|
|
|
|
|
2016-12-23 10:31:26 +01:00
|
|
|
# For multiple feed, add them with "," without space
|
|
|
|
# e.g.: tcp://127.0.0.1:5556,tcp://127.0.0.1:5557
|
2014-08-29 19:37:56 +02:00
|
|
|
[ZMQ_Global]
|
2016-02-04 15:32:50 +01:00
|
|
|
#address = tcp://crf.circl.lu:5556
|
2018-02-27 16:16:57 +01:00
|
|
|
address = tcp://127.0.0.1:5556,tcp://crf.circl.lu:5556
|
2014-08-29 19:37:56 +02:00
|
|
|
channel = 102
|
2017-01-13 14:54:43 +01:00
|
|
|
bind = tcp://127.0.0.1:5556
|
2014-08-29 19:37:56 +02:00
|
|
|
|
|
|
|
[ZMQ_Url]
|
|
|
|
address = tcp://127.0.0.1:5004
|
|
|
|
channel = urls
|
|
|
|
|
2014-12-22 16:29:05 +01:00
|
|
|
[ZMQ_FetchedOnion]
|
|
|
|
address = tcp://127.0.0.1:5005
|
|
|
|
channel = FetchedOnion
|
2014-09-30 16:55:16 +02:00
|
|
|
|
2014-12-22 16:29:05 +01:00
|
|
|
[RedisPubSub]
|
|
|
|
host = localhost
|
|
|
|
port = 6381
|
|
|
|
db = 0
|