2017-06-01 17:00:32 +02:00
|
|
|
#!/usr/bin/env python3
|
2017-05-30 12:21:40 +02:00
|
|
|
# -*- coding: utf-8 -*-
|
2017-04-27 13:58:49 +02:00
|
|
|
|
|
|
|
misp_url = 'YOUR_MISP_URL'
|
2018-05-02 19:08:22 +02:00
|
|
|
misp_key = 'YOUR_KEY_HERE' # The MISP auth key can be found on the MISP web interface under the automation section
|
2017-04-27 13:58:49 +02:00
|
|
|
misp_verifycert = True
|
2018-05-02 19:08:22 +02:00
|
|
|
spamtrap = False
|
2018-05-11 20:50:19 +02:00
|
|
|
default_distribution = 0
|
2021-09-30 07:55:39 +02:00
|
|
|
default_threat_level = 4
|
2018-05-11 20:50:19 +02:00
|
|
|
default_analysis = 1
|
2021-09-30 07:55:39 +02:00
|
|
|
id_tag = 'host:m2m:tld'
|
2021-01-25 17:54:49 +01:00
|
|
|
freetext = False
|
2018-05-02 19:08:22 +02:00
|
|
|
|
2023-11-10 23:40:30 +01:00
|
|
|
# O365MISPClient config
|
|
|
|
o365_freetext = False # must be enabled in addition to the above freetext to use this on o365 email messages
|
|
|
|
o365_client_id = 'YOUR_O365_CLIENT_ID'
|
|
|
|
o365_client_secret = 'YOUR_O365_CLIENT_SECRET'
|
|
|
|
o365_tenant_id = 'YOUR_O365_TENANT_ID'
|
|
|
|
o365_resource = 'YOUR_O365_INBOX' # misp@yourdomain.com or whatever inbox you are reading mail from
|
|
|
|
o365_scopes = [
|
|
|
|
'offline_access', # Highly recommended to add this. If not you will have to re-authenticate every hour.
|
|
|
|
'https://graph.microsoft.com/Mail.Read', # To read my mailbox
|
|
|
|
# 'https://graph.microsoft.com/Mail.Read.Shared' # To read another user/shared mailbox
|
|
|
|
]
|
|
|
|
|
2018-05-11 20:50:19 +02:00
|
|
|
body_config_prefix = 'm2m' # every line in the body starting with this value will be skipped from the IOCs
|
2018-04-03 11:09:54 +02:00
|
|
|
m2m_key = 'YOUSETYOURKEYHERE'
|
2018-05-04 14:24:02 +02:00
|
|
|
m2m_benign_attachment_keyword = 'benign'
|
2017-04-27 13:58:49 +02:00
|
|
|
|
2018-08-02 17:04:46 +02:00
|
|
|
enable_dns = True
|
2017-05-23 15:19:31 +02:00
|
|
|
debug = False
|
2017-04-27 13:58:49 +02:00
|
|
|
nameservers = ['149.13.33.69']
|
2018-05-02 19:08:22 +02:00
|
|
|
email_subject_prefix = 'M2M'
|
2018-05-11 17:33:58 +02:00
|
|
|
attach_original_mail = False
|
2019-11-16 16:47:43 +01:00
|
|
|
ignore_carrier_mail = False
|
2019-11-19 10:13:36 +01:00
|
|
|
ignore_nullsize_attachments = False
|
2017-04-27 13:58:49 +02:00
|
|
|
|
2017-05-31 14:52:47 +02:00
|
|
|
excludelist = ('google.com', 'microsoft.com')
|
2023-11-10 23:40:30 +01:00
|
|
|
externallist = ('virustotal.com', 'malwr.com', 'hybrid-analysis.com', 'emergingthreats.net', 'urlscan.io',
|
|
|
|
'abuse.ch', 'tria.ge', 'bleepingcomputer.com', 'any.run', 'urlvoid.com', 'intezer.com')
|
2017-05-31 14:52:47 +02:00
|
|
|
internallist = ('internal.system.local')
|
2018-05-02 19:08:22 +02:00
|
|
|
noidsflaglist = ('myexternalip.com', 'ipinfo.io', 'icanhazip.com', 'wtfismyip.com', 'ipecho.net',
|
|
|
|
'api.ipify.org', 'checkip.amazonaws.com', 'whatismyipaddress.com', 'google.com',
|
|
|
|
'dropbox.com'
|
|
|
|
)
|
2017-05-17 09:54:24 +02:00
|
|
|
|
|
|
|
# Stop parsing when this term is found
|
2017-06-30 08:35:50 +02:00
|
|
|
stopword = 'Whois & IP Information'
|
2017-04-27 13:58:49 +02:00
|
|
|
|
2017-05-30 16:35:29 +02:00
|
|
|
# Ignore lines in body of message containing:
|
2018-05-02 19:08:22 +02:00
|
|
|
ignorelist = ("From:", "Sender:", "Received:", "Sender IP:", "Reply-To:", "Registrar WHOIS Server:",
|
|
|
|
"Registrar:", "Domain Status:", "Registrant Email:", "IP Location:",
|
|
|
|
"X-Get-Message-Sender-Via:", "X-Authenticated-Sender:")
|
2017-05-30 16:35:29 +02:00
|
|
|
|
2017-12-20 14:26:30 +01:00
|
|
|
# Ignore (don't add) attributes that are on server side warning list
|
2018-05-02 19:08:22 +02:00
|
|
|
enforcewarninglist = True
|
2017-12-20 14:26:30 +01:00
|
|
|
|
2017-12-20 16:08:27 +01:00
|
|
|
# Add a sighting for each value
|
2018-05-02 19:08:22 +02:00
|
|
|
sighting = True
|
|
|
|
sighting_source = "YOUR_MAIL_TO_MISP_IDENTIFIER"
|
2017-12-20 16:08:27 +01:00
|
|
|
|
2018-05-11 16:15:16 +02:00
|
|
|
# Remove "Re:", "Fwd:" and {Spam?} from subject
|
|
|
|
# add: "[\(\[].*?[\)\]]" to remove everything between [] and (): i.e. [tag]
|
2023-11-10 23:40:30 +01:00
|
|
|
removelist = (r"Re:", r"Fwd:", r"\{Spam\?\} ", r"RE:", r"FW:")
|
2017-05-30 16:35:29 +02:00
|
|
|
|
2017-04-27 13:58:49 +02:00
|
|
|
# TLP tag setup
|
|
|
|
# Tuples contain different variations of spelling
|
2023-11-10 23:40:30 +01:00
|
|
|
tlptags = {'tlp:amber': ['tlp:amber', 'tlp: amber', 'tlp amber', 'tlp :amber'],
|
|
|
|
'tlp:amber+strict': ['tlp:amber+strict', 'tlp: amber+strict', 'tlp amber+strict', 'tlp :amber+strict'],
|
|
|
|
'tlp:green': ['tlp:green', 'tlp: green', 'tlp green', 'tlp :green'],
|
|
|
|
'tlp:white': ['tlp:white', 'tlp: white', 'tlp white', 'tlp :white'],
|
|
|
|
'tlp:clear': ['tlp:clear', 'tlp: clear', 'tlp clear', 'tlp :clear'],
|
|
|
|
'tlp:red': ['tlp:red', 'tlp: red', 'tlp red', 'tlp :red']
|
2018-05-02 19:08:22 +02:00
|
|
|
}
|
2017-05-29 17:26:39 +02:00
|
|
|
tlptag_default = sorted(tlptags.keys())[0]
|
2017-04-27 13:58:49 +02:00
|
|
|
|
2018-05-02 19:08:22 +02:00
|
|
|
malwaretags = {'locky': ['ecsirt:malicious-code="ransomware"', 'misp-galaxy:ransomware="Locky"'],
|
|
|
|
'jaff': ['ecsirt:malicious-code="ransomware"', 'misp-galaxy:ransomware="Jaff"'],
|
|
|
|
'dridex': ['misp-galaxy:tool="dridex"'],
|
|
|
|
'netwire': ['Netwire RAT'],
|
|
|
|
'Pony': ['misp-galaxy:tool="Hancitor"'],
|
|
|
|
'ursnif': ['misp-galaxy:tool="Snifula"'],
|
|
|
|
'NanoCore': ['misp-galaxy:tool="NanoCoreRAT"'],
|
2023-11-10 23:40:30 +01:00
|
|
|
'trickbot': ['misp-galaxy:tool="Trick Bot"'],
|
|
|
|
'agenttesla': ['misp-galaxy:mitre-malware="Agent Tesla - S0331"'],
|
|
|
|
'formbook': ['misp-galaxy:malpedia="Formbook"'],
|
|
|
|
'remcos': ['misp-galaxy:mitre-tool="Remcos - S0332"'],
|
|
|
|
'snake keylogger': ['misp-galaxy:malpedia="404 Keylogger"'],
|
|
|
|
'icedid': ['misp-galaxy:malpedia="IcedID"'],
|
|
|
|
'zloader': ['misp-galaxy:malpedia="Zloader"'],
|
|
|
|
'lokibot': ['misp-galaxy:mitre-malware="Lokibot - S0447"'],
|
|
|
|
'valyria': ['misp-galaxy:malpedia="POWERSTATS"'],
|
|
|
|
'guloader': ['misp-galaxy:mitre-malware="GuLoader - S0561"'],
|
|
|
|
'avemaria': ['misp-galaxy:mitre-malware="WarzoneRAT - S0670"'],
|
|
|
|
'warzone': ['misp-galaxy:mitre-malware="WarzoneRAT - S0670"'],
|
|
|
|
'hancitor': ['misp-galaxy:malpedia="Hancitor"'],
|
|
|
|
'async': ['misp-galaxy:malpedia="AsyncRAT"'],
|
|
|
|
'emotet': ['misp-galaxy:mitre-malware="Emotet - S0367"']
|
2018-05-02 19:08:22 +02:00
|
|
|
}
|
2017-06-30 08:35:50 +02:00
|
|
|
|
2017-04-27 13:58:49 +02:00
|
|
|
# Tags to be set depending on the presence of other tags
|
2023-11-10 23:40:30 +01:00
|
|
|
dependingtags = {'tlp:white': ['circl:osint-feed'],
|
|
|
|
'tlp:clear': ['circl:osint-feed']
|
2018-05-02 19:08:22 +02:00
|
|
|
}
|
2017-04-27 13:58:49 +02:00
|
|
|
|
2018-05-02 19:08:22 +02:00
|
|
|
# Known identifiers for forwarded messages
|
|
|
|
forward_identifiers = {'-------- Forwarded Message --------', 'Begin forwarded message:'}
|
2017-05-29 15:36:27 +02:00
|
|
|
|
2017-05-22 09:43:44 +02:00
|
|
|
# Tags to add when hashes are found (e.g. to do automatic expansion)
|
2018-05-02 19:08:22 +02:00
|
|
|
hash_only_tags = {'TODO:VT-ENRICHMENT'}
|
2017-05-29 17:26:39 +02:00
|
|
|
|
2017-12-20 14:26:30 +01:00
|
|
|
# If an attribute is on any MISP server side `warning list`, skip the creation of the attribute
|
|
|
|
skip_item_on_warninglist = True
|
2019-07-18 16:12:44 +02:00
|
|
|
|
|
|
|
vt_key = None
|