Commit Graph

311 Commits (a61caa3a6a541e6f9761ae99c033c7457050bc0b)

Author SHA1 Message Date
mokaddem d6093b9659 chg: [object:fromAttributes] Method only accesible via AJAX and regular
users can use the feature
2019-06-12 11:17:17 +02:00
mokaddem 8d2c55fa69 Merge branch '2.4' of github.com:MISP/MISP into mergeAttributeIntoObjects 2019-06-05 12:02:17 +02:00
iglocska 3bcaab013e
new: [cleanup] Added admin tool to remove all published empty events
- part of the solution to the empty event sync issue introduced in 2.4.107
- skips the event blacklisting
2019-06-04 19:45:28 +02:00
iglocska aae9307106
new: [Sync] Add a tool to create MISP sync configuration JSONs and to ingest them, fixes #4696
- sync user can log into remote instance, extract config JSON
- paste it into own instance as site admin to add MISP sync connection
2019-05-30 14:42:29 +02:00
mokaddem b2766f2adf chg: [ACL] Updated routing 2019-05-24 16:14:38 +02:00
mokaddem 44d71a327a chg: [object:fromAttributes] Shows selected types and started
implementaion of the actual object creation - WiP
2019-05-20 14:30:20 +02:00
mokaddem a90ac883aa chg: [object:fromAttribute] Continue of web and controller
implementation - WiP
2019-05-16 17:13:18 +02:00
mokaddem ee735f00d4 new: [update] Injected update-related files/changes from zoidberg 2019-04-26 09:45:03 +02:00
iglocska 156d979133 fix: [ACL] HELLO @RichieB2B! fixed invalid capitalisation in the queryACL 2019-04-10 10:31:21 +02:00
iglocska 29598c2475 new: [API] Update JSON exposed to the API 2019-04-10 10:09:25 +02:00
mokaddem e4bc67463b Merge branch '2.4' of github.com:MISP/MISP into decaying 2019-04-10 08:39:13 +02:00
Steve Clement c8274c476e
Merge pull request #4427 from mokaddem/submoduleUpdatev3
Submodule updateV3
2019-04-05 18:18:35 +09:00
mokaddem 3778c4686b fix: [acl] added route 2019-04-05 10:54:32 +02:00
Andras Iklody c484f01449
Fix: [acl] added missing entry
This message was sent from my Blackberry.
2019-04-04 17:35:34 +02:00
iglocska c6974d217e Merge branch '2.4' of github.com:MISP/MISP into 2.4 2019-04-01 16:21:30 +02:00
iglocska dc39255be5 fix: [ACL] Added ACL for the new cache searches 2019-04-01 16:16:16 +02:00
iglocska 76d14c00cb Merge branch 'thumbnail' into 2.4 2019-03-29 20:29:37 +01:00
Steve Clement 823ea745be
Merge pull request #4337 from mokaddem/submoduleDiagnostic
Submodule diagnostic
2019-03-27 17:27:53 +01:00
chrisr3d 4858b0181c
fix: [ACL Component] Added new function (for new modules format) in the list 2019-03-25 15:53:15 +01:00
mokaddem 016893210d new: [cluster] Display heatmap on the Att&ck Matrix for all tagged data.
fix #4344
2019-03-20 14:30:05 +01:00
iglocska 7141f70b20 Merge branch 'kafka' into 2.4 2019-03-19 17:23:05 +01:00
iglocska e028c1a886 fix: [ACL] fixed 2019-03-19 16:32:20 +01:00
iglocska 9a863b3bb2 fix: [ACL] Fixed ACL 2019-03-19 11:18:12 +01:00
iglocska 7fbc4dc34c new: [REST client] Added history/bookmarks 2019-03-19 10:55:27 +01:00
mokaddem 600e4b0573 new: [diagnostic] Fetch submodules git status 2019-03-18 16:17:10 +01:00
Nikos Filippakis 9d59b10368 Publish events to Kafka
Signed-off-by: Nikos Filippakis <nikolaos.filippakis@cern.ch>
2019-03-18 15:53:22 +01:00
mokaddem 051a7594e1 Merge branch '2.4' of github.com:MISP/MISP into thumbnail 2019-03-18 08:49:34 +01:00
Alexandre Dulaunoy ae2c513b62
Merge pull request #4309 from mokaddem/extendedDistributionGraph
Improvement on distribution visualization
2019-03-15 16:05:17 +01:00
mokaddem aa03357aaa fix: [ACL] Whitelisted `genDistributionGraph` 2019-03-15 15:32:18 +01:00
mokaddem 749c9ea544 fix: [ACL] Whitelisted `viewPicture` 2019-03-15 15:19:39 +01:00
iglocska 42e1777a50 new: [galaxies] Allow deleting full galaxies 2019-03-15 14:33:31 +01:00
iglocska fc34510eda new: [Feeds] New overlap tool finished
- compare a feed against a combination of feeds/servers to find if you can cover the contents with a combination of other cached feeds
2019-03-10 18:09:46 +01:00
mokaddem 8e78d77cc5 chg: [decaying] UI skeleton - WiP 2019-03-05 14:54:19 +01:00
Steve Clement f03c519038
Merge pull request #3658 from ancailliau/issue-3639
Fixes issue #3639
2019-03-03 07:35:13 +05:30
iglocska 99b2dad95d fix: [ACL] added toggleToIDS 2019-02-27 20:29:56 +01:00
mokaddem 9fa063cbe8 chg: [galaxy_matrix] renamed view_matrix into view_galaxy_matrix 2019-02-15 09:41:17 +01:00
mokaddem 12ed3457e8 chg: [galaxy_matrix] cleanup in variable names to be more generic 2019-02-15 09:24:52 +01:00
iglocska 09cbbe3b93 Merge branch '2.4' of github.com:MISP/MISP into 2.4 2019-02-10 21:36:03 +01:00
iglocska b3d94d1ebe fix: [ACL] tags/search added to the ACL 2019-02-10 21:34:45 +01:00
Christophe Vandeplas 67efc70bf5 fix: [style] consistent space indentation 2019-02-10 13:08:55 +01:00
iglocska 13993eb1c7 new: [Tag collections] Export/import tag collections added 2019-01-21 15:15:10 +01:00
iglocska 498a7ae77c new: [feeds] Opened up feed inspection to host org users and added servers to overlap matrix 2019-01-20 10:19:05 +01:00
iglocska b1d1597468 fix: [ACL] ACL updated 2019-01-18 16:18:23 +01:00
iglocska 76497420fa new: [publishing] Unpublish function added
- users were jumping through hoops to unpublish an event
2019-01-17 08:27:16 +01:00
iglocska c09992d2d9 fix: [ACL] Added ajax function to ACL 2019-01-06 17:37:13 +01:00
iglocska 6aa366138c fix: [ACL] Added missing function 2019-01-02 10:06:39 +01:00
iglocska 760dbed37d new: [tag collections] First feature complete minimal version of the tag collection system 2019-01-01 16:38:57 +01:00
iglocska 8a223f6ace fix: [ACL] ACL updated 2018-11-23 15:52:18 +01:00
iglocska 2d0259ce13 fix: [CS] coding standards script re-run 2018-11-23 14:11:33 +01:00
mokaddem 5c1522bc74 fix: [acl] bumped ACLComponent 2018-10-30 22:00:04 +01:00
Sami Mokaddem d1fb94c332 fix: [ACL] bumped queryACL 2018-10-23 13:28:48 +02:00
Sami Mokaddem 731a4d5e2b new: [Sightings/API] Added possiblity to get sightings based on a
timerange/source/...
2018-10-22 23:27:58 +02:00
iglocska 7a01de5359 new: [API] Added a way to use the API to throw values at the warninglist for quick evaluations of the values 2018-10-16 17:57:14 +02:00
iglocska e7ae566c40 fix: [ACL] Added exportSearch to the ACL 2018-10-04 23:07:44 +02:00
iglocska 8280994a03 fix: [ACL] Appease Travis (admin only function explicitly named) 2018-09-14 08:30:05 +02:00
Antoine Cailliau d7f3f27208 Fixes issue #3639 2018-09-10 13:45:23 +02:00
iglocska 17e16e34f1 new: [ACL] Added soft validation for available API enumeration 2018-09-05 07:42:20 +02:00
iglocska 630a1a0150 fix: [ACL] getApiInfo added to acl 2018-09-02 05:54:40 +02:00
iglocska 40d7c216d8 fix: [ACL] exclude afterfilter from the api checks 2018-08-31 16:08:46 +02:00
iglocska c8fcb16881 new: [feature] Built in REST client added to test / interact with the API directly from MISP
- no more shitty chrome extensions that crash during trainings, rejoice!
2018-08-08 11:29:38 +02:00
iglocska a81894f14c chg: [CS] Changed to PSR-2
- to make contributions easier, adopted PSR-2
- used php-cs-fixer to rework the style
- *sniff sniff* Goodbye tab indentation
2018-07-19 11:48:22 +02:00
Sami Mokaddem 692b410f92 chg: [eventGraph] refacto after comments from the Overmind 2018-07-10 08:43:38 +00:00
Sami Mokaddem 75dd257941 chg: [eventGraph] renaming EventNetworkHistory into simply EventGraph 2018-07-06 13:17:59 +00:00
Sami Mokaddem f836b5650e Merge remote-tracking branch 'upstream/2.4' into sharingGraph 2018-07-06 09:23:50 +00:00
Sami Mokaddem e1c9b21b8e chg: [ACL] bumped to reflect networkHistory controller 2018-07-06 09:12:26 +00:00
Sami Mokaddem 93ba5617ea chg: [eventGraph] Implemented saving/deleting feature 2018-07-05 11:57:28 +00:00
iglocska c3158b50ba new: [edit strategy API] To support a smoother integration with the Hive, new API that describes what the edit strategy is for an event
- GET on /events/getEditStrategy/[id]
  - where id can be either a local ID or a UUID

- returns a JSON dictionary with the following fields:
  - strategy: edit | extend (edit if it's an own event, extend otherwise)
  - extensions: list of dictionaries with existing extensions created by the user's org (containing the id, uuid, info fields)

- The algorithms implementing this should prioritise as such:

1. Check if user can edit the event (strategy == edit) - if yes, edit
2. If no, check if extensions exist - if yes, edit one of those
3. If no, create a new extension to the original event
2018-07-02 17:29:53 +02:00
Sami Mokaddem 6637d19e46 fix: bump query_version and updated queryACL 2018-06-22 13:37:49 +00:00
Sami Mokaddem 1f685bf625 fix: [attackMatrix] added missing entries in ACL component 2018-06-18 12:21:45 +00:00
iglocska 1a980185d4 fix: [ACL] added new functions to the ACL 2018-06-12 16:39:08 +02:00
iglocska e3eb71b29a new: [ACL] Added new role permission: publish_zmq
- permission flag to use the "publish to ZMQ" button
2018-06-07 17:52:01 +02:00
iglocska a21fcadd94 fix: Ignore camelised vs underscored controller name differences in the ACL 2018-05-17 09:39:15 +02:00
iglocska 2be71c596c version bump 2018-05-14 23:22:18 +02:00
iglocska db7419c96e fix: Don't lowercase the controllername for the ACL Component 2018-05-10 11:55:10 +02:00
iglocska e1721e0177 fix: [ACL] Made the ACL system's behaviour more lax when it comes to capitalisation mistakes in the URL, fixes #3240 2018-05-09 13:23:30 +02:00
iglocska 05cf0563e1 new: First implementation of the Noticelist system ready 2018-05-07 10:43:21 +02:00
Sami Mokaddem 56b37d08fc Merge remote-tracking branch 'upstream/2.4' into distributionGraph 2018-04-25 07:08:54 +00:00
iglocska e0f975e4cc fix: Added event enrichment to the ACL 2018-04-24 17:32:20 +02:00
Sami Mokaddem 99af821871 Updated ACLComponent 2018-04-24 10:09:50 +00:00
iglocska 3c438243f4 Merge branch '2.4' of github.com:MISP/MISP into 2.4 2018-04-17 13:45:04 +02:00
iglocska 9b2e212b3d new: Added getEventInfoById API 2018-04-17 13:43:47 +02:00
Sami Mokaddem 56daf7f494 updated ACLComponent 2018-04-16 12:43:12 +00:00
Sami Mokaddem 921224ed40 Merge branch 'quick-fix-metacategory-graph' into ref_graph 2018-04-06 07:50:27 +00:00
Sami Mokaddem 5e83caf8fb Added retreiving of object templates in order to let the user choose the field we want to see in the event graph 2018-03-29 16:05:19 +00:00
iglocska d547726faa fix: Tied the new diagnostic tool into the ACL 2018-03-26 12:11:50 +02:00
Sami Mokaddem 4ec83b9903 Registrered funciton in ACLComponent 2018-03-23 07:58:39 +00:00
iglocska 824ebb5aea fix: Tied the clearjobs function into the ACL and fixed a small text error 2018-03-14 02:31:25 +01:00
iglocska 39b5d06f29 new: Temp diagnostic tool for orphaned object attributes 2018-03-01 22:34:20 +01:00
iglocska ef3f28a93a fix: Various fixes to the module api
- query function renamed to query enrichment
- added check for disabled modules and for modules that the current user is not allowed to use
- removed the module config from the index function to avoid exposing API keys / credentials to users
- some formating fixes
2018-02-16 14:36:57 +01:00
Juan C. Montes 6b8e508cf0 fix: ModulesController 2018-02-16 11:22:28 +01:00
Juan C. Montes 4d71eeb72a
new: ModulesQueryAPI
ModulesQuery controller to can communicate from MISP API to misp_modules
2018-02-13 13:31:10 +01:00
iglocska 65f032fcca fix: Hop over commented out functions in the queryACL tests 2018-02-09 15:06:35 +01:00
iglocska 9af6130d43 new: Added STIX import directly to the UI 2018-02-09 11:30:28 +01:00
iglocska 4b722e0b61 fix: Added new APIs to ACL component
- wooooops
2018-02-02 14:09:15 +01:00
iglocska 771a262b0d fix: Missing action added to ACL system 2018-01-16 14:56:30 +01:00
iglocska dedfea3610 new: Mass enable/disable feeds
- protecting the sanity of MISP admins since 2012!
2018-01-15 17:25:11 +01:00
iglocska 3fb5ccdab2 fix: tie warninglist delete into the ACL 2017-12-22 13:16:31 +01:00
iglocska 9259f072fe chg: ACL updated 2017-10-08 20:33:59 +02:00
truckydev f607398852 user right update
Make all user access to /attributes/describeTypes.json
2017-09-27 17:52:36 +02:00
iglocska 242fbce3e1 fix: ACL updated 2017-09-18 00:42:26 +02:00
iglocska aa07299abe Merge branch '2.4' into objects_wip 2017-08-10 07:29:50 +02:00
iglocska f9053ed3e3 chg: Restrict tag editor permission to only create tags
- deleting/eding tags indirectly modifies events created by others
- reduced to site admin only functionality
2017-08-09 14:22:54 +02:00
iglocska 092b2247da fix: Add object functions to ACL 2017-07-05 08:43:17 +02:00
iglocska c9784cc4f8 fix: Moved attachment access diagnostic tool to attributes controller 2017-06-18 10:12:48 +02:00
root e489f431d9 Adding small diagnostic on Server Setting > Diagnostics page to check if some attachments
referenced in database doesn't exist on filesystem.
2017-05-11 14:11:08 +02:00
iglocska 96574ec335 new: First implementation of the feed analysis system 2017-05-08 14:22:27 +02:00
iglocska ded4cb2769 fix: Added missing ACL entry 2017-03-24 10:33:58 +01:00
iglocska e79ba76c43 fix: Some ACL tightening 2017-03-02 09:57:23 +01:00
iglocska e9edeed22c new: User management convenience functions added
- quick e-mail: send an e-mail to a user quickly
- orgadmin: see the org admins of a user and contact them
- pgp key issues shown on the user view
- pgp fingerprint shown on the user view
- copy paste auth keys and pgp keys quickly by clicking on them
2017-02-22 17:12:32 +01:00
iglocska 9fbf6a0569 chg: sightings role added to ACL 2017-02-20 11:13:02 +01:00
iglocska fde867d7a8 fix: ACL updated 2017-02-17 10:05:05 +01:00
iglocska de1b3cf4c8 fix: Added new functionality to the ACL 2017-01-31 10:52:32 +01:00
iglocska 76c0cb4e52 new: Add and remove tags from object by uuid
- /tags/attachTagToObject/uuid/tag
- /tags/removeTagFromObject/uuid/tag

- tag can be tag ID or tag name (must be an exact match)
- Affects events and attributes
2017-01-27 19:05:43 +01:00
Iglocska e5d658078a fix: ACL updated for attribute level tagging 2017-01-18 16:45:00 +01:00
iglocska 4ad022b03c Merge branch '2.4' into feature/attribute-tagging 2017-01-16 16:15:06 +01:00
iglocska 2b187d48fc new: Add a new api to check the supported PyMISP version 2017-01-08 20:20:49 +01:00
iglocska b0585c0e91 fix: Added sightings index to the ACL 2017-01-08 03:07:32 +01:00
iglocska 9ce46689b6 fix: Updated the ACL 2016-12-31 09:36:45 +01:00
iglocska 5b54171364 fix: Allow users to fetch their PGP keys 2016-12-29 13:34:41 +01:00
iglocska 7146652059 Merge branch '2.4' into feature/attribute-tagging 2016-12-26 23:30:21 +01:00
iglocska b1fa7db672 fix: Added ACL changes 2016-12-22 17:51:46 +01:00
Iglocska bfc8b65f0d fix: Galaxy permission issue fixes #1
- affects #1731
2016-12-08 10:30:29 +01:00
Iglocska 11964f791b fix: removed a duplicate ACL entry 2016-12-07 16:54:38 +01:00
Andras Iklody 44ec75e462 Merge pull request #1726 from liviuvalsan/bro_export_improvements
Performance improvements, bug fixes and new features for the export to Bro
2016-12-07 16:52:15 +01:00
Liviu Valsan 4c022beafc - Performance improvements when exporting a large number of attributes into Bro format.
- Fixed file header formatting for the export to Bro format (tabs used consistently).
- Computing the time needed for generating the export to Bro format when done using a background job.
- When generating the Bro export from the UI all the attributes are generated in one single text file similar to the CSV export instead of a zip file with different files inside.
- Changed the file extension of Bro export files from ".intel" to ".txt".
- Removed the allowNonIDS option from the Bro export as it doesn’t make sense to have it (Bro is an IDS).
- Fixed some of the API endpoints which were not accepted (ACL issues).
- Added support for a list of events that should be / should not be included in the export.
- Added a new "meta.desc" column (added in Bro 2.5, see https://www.bro.org/sphinx/frameworks/intel.html) containing the description of the event and of the attribute.
- Sanitized the exported data for Bro.
- Fixed a number of value substitutions which were imported from Snort/Suricata and which were not working for Bro. Did instead substitutions needed for Bro.
2016-12-07 16:33:17 +01:00
Iglocska 761cf6cec7 new: Tied the galaxies into the ACL 2016-12-07 07:34:45 +01:00
Iglocska c76d358535 new: Added new statistics page, fixes #1648, fixes #1557
- brought back the quick organisation overview as it's a much missed feature
- added treemap for tags
- brought attribute histogram into statistics page

- more coming in the future
2016-11-04 13:14:03 +01:00
Richard van den Berg 36971b57cd Allow merging of event attributes 2016-10-01 12:47:53 +02:00
Andreas Ziegler 05761308e8 new: add&remove attributetags on event view 2016-09-29 16:52:47 +02:00
Andreas Ziegler 25e52a6786 chg: remove some references to variables 2016-09-15 17:08:58 +02:00
Cristian Bell f37963fde4 Merge branch 'fix_1311_only_show_API/authkey_to_user_with_rights' of https://github.com/cristianbell/MISP into cristianbell-fix_1311_only_show_API/authkey_to_user_with_rights 2016-09-02 15:35:11 +02:00
iglocska 003fb1885c fix: Added the default role selector to the ACLComponent 2016-09-01 09:21:51 +02:00
Cristian Bell 7774f52fe7 chg: only show API/authkey to user with API key rights, fixes #1311 2016-08-23 16:20:39 +02:00
Iglocska 3aca8618b5 fix: Missing ACL entries added 2016-08-22 18:11:54 +02:00
Cristian Bell 72b9bdbb84 chg: redundant members list and organisations page 2016-08-04 13:45:10 +02:00
Iglocska e24c421a00 Merge branch 'perm_delegate' into 2.4 2016-07-18 00:50:09 +02:00
Iglocska c84c24502c fix: Added taxonomies/delete to the ACL component 2016-07-12 16:58:01 +02:00
Richard van den Berg ca2fb7de96 - Allow delegation when unpublishedprivate is set
- Use perm_delegate instead of perm_publish for delegation
2016-07-06 09:36:13 +02:00
Alexandre Dulaunoy d661d216c2 Chg: describeTypes broaden access to non-automation users too. 2016-06-09 15:49:18 +02:00
Andreas Ziegler 1d06f25b38 chg: add newline character before EOF to non-minified (text-)files 2016-06-06 10:09:55 +02:00
Andreas Ziegler 0fe692c56a remove whitespace at end of line 2016-06-04 01:10:45 +02:00
Andreas Ziegler 898ea1d97c remove whitespace (space/tab) from empty lines 2016-06-04 01:08:16 +02:00
Iglocska f08ec04426 new: Enable/disable feed via API
- simply POST to /feeds/enable/feed_id or /feeds/disable/feed_id to enable and disable a feed
2016-05-26 01:39:31 +02:00
Iglocska 21111498c3 new: Added Statixtics for taxonomy and tag usage, fixes 1158 2016-05-22 23:35:24 +02:00
Andreas Ziegler dc0974a55b misc cleanup 2016-05-21 05:10:49 +02:00
Iglocska 6b6877099a fix: Added the option for users to see and undelete attributes if an event was created by their org, fixes #1144
- Also some minor fixes to the ACL
2016-05-20 11:20:03 +02:00
Iglocska d02adf2085 new: Added the news functionality back
- admins can add/edit/delete news items
- users get redirected if there is a newsitem that they haven't seen yet
2016-05-20 01:17:26 +02:00
Iglocska 6b83e988f7 chg: Small comment fix 2016-04-29 16:15:19 +02:00
Iglocska 65f40aea90 fix: Fixed an ACL issue preventing normal users from viewing the instance version
- this is required by the enrichment modules
2016-04-29 15:59:02 +02:00
Iglocska d826d62fd0 fix: Fixed some issues with the favourite tags 2016-04-28 16:16:23 +02:00
Iglocska a1a27da0cf First version of the warnings finished 2016-04-22 15:03:20 +02:00
Iglocska 68d6cae7ac Org admins could not see the roles index 2016-04-19 10:32:22 +02:00
Iglocska a6c880c4d2 Fix to the URL generation
- sometimes the URLs are inconsistent in links within MISP (/shadowAttributes vs shadow_attributes)
- the URL generation now takes both cases into consideration
2016-04-18 15:39:55 +02:00
Iglocska 7c6ef14621 Some ACL fixes 2016-04-18 15:32:09 +02:00
Iglocska a20ba21774 change_pw was blocked for normal users 2016-04-18 14:52:05 +02:00
Iglocska b8f34ee844 Added some statistics APIs for attribute types / categories 2016-04-18 14:40:08 +02:00
Iglocska 1ecc4c2f37 Fixed a capitalisation fail 2016-04-18 14:06:17 +02:00
Iglocska b39d178211 some small changes 2016-04-18 09:46:08 +02:00
Iglocska 057ff5e831 Small fixes 2016-04-18 09:14:36 +02:00
Iglocska 92952cc5e4 Rework of the ACL 2016-04-18 03:19:01 +02:00
Iglocska d56f31e888 Work on the new ACL system 2016-04-17 23:13:39 +02:00