Sebdraven
54d996cb00
add history dns
2018-07-11 09:39:09 +02:00
Sebdraven
dcdb6e5895
switch type ip
2018-07-11 09:02:47 +02:00
Sebdraven
42c362d2fd
refactoring expand_whois
2018-07-11 09:00:23 +02:00
Sebdraven
41635d43c7
correct typo
2018-07-11 08:49:59 +02:00
Sebdraven
3a96e189ed
add ipv6 and ipv4
2018-07-11 08:43:23 +02:00
Sebdraven
f2333a4978
change type
2018-07-10 16:55:13 +02:00
Sebdraven
9e6162a434
change type
2018-07-10 16:53:06 +02:00
Sebdraven
26950ea7de
change loop
2018-07-10 16:51:31 +02:00
Sebdraven
e9747a3379
add time sleep in each request
2018-07-10 16:41:44 +02:00
Sebdraven
602da3d1a3
control return of records
2018-07-10 16:35:01 +02:00
Sebdraven
495c720d0f
add history ipv4
2018-07-10 16:31:39 +02:00
Sebdraven
21794249d0
add logs
2018-07-10 15:17:37 +02:00
Sebdraven
b677cd5fc7
change categories
2018-07-10 15:16:02 +02:00
Sebdraven
1d100833a4
concat results
2018-07-10 15:12:27 +02:00
Sebdraven
1223d93d52
change name keys
2018-07-10 15:07:54 +02:00
Sebdraven
714c15f079
change return value
2018-07-10 15:05:10 +02:00
Sebdraven
e1a1648f14
add logs
2018-07-10 15:01:04 +02:00
Sebdraven
f710162bed
change errors
2018-07-10 14:59:39 +02:00
Sebdraven
2a8fb76e84
add logs
2018-07-10 14:56:20 +02:00
Steve Clement
562a6b1308
- Removed test modules from view
...
- Moved skeleton expansion module to it's proper place
2018-07-03 08:27:54 +02:00
chrisr3d
90e42c0305
fix: Put the stix2-pattern library import in a try statement
...
--> Error more easily caught
2018-07-02 12:14:21 +02:00
chrisr3d
08d8459e1a
add: STIX2 pattern syntax validator
2018-07-02 11:38:33 +02:00
Steve Clement
549f32547d
- Reverted to <3.6 compatibility
2018-07-01 22:09:02 +08:00
Steve Clement
9f0313a97e
- Fixed log output
2018-06-30 12:01:21 +08:00
Steve Clement
184065cf74
- Forgot to import sys
2018-06-30 11:58:44 +08:00
Steve Clement
ffce2aa5cc
- Added logger functionality for debug sessions
2018-06-30 11:52:12 +08:00
Steve Clement
2f5dd9928e
- content was already a wand.obj
2018-06-30 11:38:26 +08:00
Steve Clement
90f2fe9d19
Merge remote-tracking branch 'upstream/master'
2018-06-30 01:05:01 +08:00
Steve Clement
f97359de6a
Merge branch 'master' of github.com:SteveClement/misp-modules
2018-06-30 01:04:30 +08:00
Steve Clement
ef3837077e
- Some more comments
...
- Removed libmagic, wand can handle it better
2018-06-30 00:58:25 +08:00
Sebdraven
34da5cdb76
add expand whois
2018-06-29 17:57:11 +02:00
Sebdraven
f1c6095914
typo
2018-06-29 17:26:56 +02:00
Sebdraven
78d6de9b7a
add categories and comments
2018-06-29 17:25:37 +02:00
Sebdraven
0965def6bf
add expand subdomains
2018-06-29 17:22:19 +02:00
Sebdraven
64847a8a04
add expand subdomains
2018-06-29 17:19:21 +02:00
Sebdraven
2d1adf4aa9
change categories
2018-06-29 16:30:47 +02:00
Sebdraven
0275e3ecd8
changes keys
2018-06-29 16:20:35 +02:00
Sebdraven
f3962d2d05
add status !
2018-06-29 16:17:32 +02:00
Sebdraven
09c52788b8
add methods
2018-06-29 16:11:24 +02:00
Sebdraven
cfe971a271
add expand domains
2018-06-29 15:50:26 +02:00
Sebdraven
60f772b905
add new module dnstrails
2018-06-29 11:27:36 +02:00
Christophe Vandeplas
ff793bc221
threatanalyzer_import - order of category tuned
2018-06-29 11:17:03 +02:00
Alexandre Dulaunoy
d8eeb73a4a
Merge branch 'master' into master
2018-06-29 06:49:40 +02:00
Steve Clement
c7c93b53e8
- Set tornado timeout to 300 seconds.
2018-06-29 12:02:08 +08:00
Steve Clement
fbb3617f25
- Quick comment ToDo: Avoid using Magic in future releases
2018-06-29 12:01:17 +08:00
Steve Clement
60a3fbe282
- added wand requirement
...
- fixed missing return png byte-stream
- move module import to handler to catch and report errorz
2018-06-28 23:20:38 +08:00
Steve Clement
7885017981
- fixed typo move image back in scope
2018-06-28 16:59:03 +08:00
chrisr3d
7dd8e988c0
Updated the list of modules (removed stiximport)
2018-06-28 10:51:40 +02:00
chrisr3d
b1c90b411e
add: Sigma syntax validator expansion module
...
--> Checks sigma rules syntax
- Updated the expansion modules list as well
- Updated the requirements list
2018-06-28 10:41:32 +02:00
chrisr3d
7c691af807
Updated the list of expansion modules
2018-06-28 10:39:40 +02:00
Steve Clement
59b7688bdc
- Added initial PDF support, nothing is processed yet
...
- Test to replace PIL with wand
2018-06-28 16:00:14 +08:00
milkmix
349dd99d47
added support for scheduledtasks
2018-06-24 21:13:56 +02:00
milkmix
7c037ed090
added support for service-displayname, regkey|value
2018-06-24 21:09:42 +02:00
milkmix
0c6a205136
initial implementation supporting regkey. mutexes support waiting osquery table
2018-06-23 15:51:38 +02:00
Sebdraven
785aac3e6b
add return handle domains
2018-06-22 16:18:23 +02:00
Sebdraven
87b07b89b5
add search
2018-06-22 16:15:34 +02:00
Sebdraven
396b71ef3b
add domain to expand
2018-06-22 16:06:34 +02:00
Sebdraven
de6a81d488
correct bugs
2018-06-22 16:04:14 +02:00
Sebdraven
83999d6402
add domain expansion
2018-06-22 15:57:52 +02:00
Sebdraven
96c829470d
add comment
2018-06-22 15:14:44 +02:00
Sebdraven
8d03354399
correct bugs
2018-06-22 15:12:10 +02:00
Sebdraven
e9c18b3d5f
correct comments
2018-06-22 13:03:09 +02:00
Sebdraven
e230c88c15
add threat list expansion
2018-06-22 11:59:09 +02:00
Sebdraven
1d1fd36569
change method to concat methods
2018-06-20 18:05:28 +02:00
Sebdraven
e712a31760
set status after requests
2018-06-20 18:04:12 +02:00
Sebdraven
a9b7a10c41
set status after requests
2018-06-20 18:03:34 +02:00
Sebdraven
4166475f9e
add logs
2018-06-20 18:02:12 +02:00
Sebdraven
fe00f099f6
add logs
2018-06-20 17:59:49 +02:00
Sebdraven
153d8bd340
add logs
2018-06-20 17:56:19 +02:00
Sebdraven
9195887f98
pep 8
2018-06-20 17:51:46 +02:00
Sebdraven
2afd2b8aaf
correct bug
2018-06-20 17:50:28 +02:00
Sebdraven
04e932cce0
add datascan expansion
2018-06-20 17:47:11 +02:00
Sebdraven
b56f8cfa36
add reverse infos
2018-06-20 16:30:56 +02:00
Sebdraven
d4be9d9fda
add reverse infos
2018-06-20 16:29:04 +02:00
Sebdraven
4a8a79c560
add reverse infos
2018-06-20 16:26:09 +02:00
Sebdraven
0d120af647
add reverse infos
2018-06-20 16:24:17 +02:00
Sebdraven
a24b529868
add forward infos
2018-06-20 15:33:21 +02:00
Sebdraven
d0f42c1772
add comment of attributes
2018-06-20 15:07:55 +02:00
Sebdraven
915747073a
add comment of attributes
2018-06-20 15:05:00 +02:00
Sebdraven
7eba7c0386
error loops
2018-06-20 14:53:08 +02:00
Sebdraven
d1e72676f1
error method
2018-06-20 14:50:48 +02:00
Sebdraven
3a4294391f
error type
2018-06-20 14:48:18 +02:00
Sebdraven
9427c76603
error keys
2018-06-20 14:45:06 +02:00
Sebdraven
e1bc67afad
add expansion synscan
2018-06-20 14:41:57 +02:00
Sebdraven
5426ec5380
change key access domains
2018-06-20 12:40:52 +02:00
Sebdraven
7a3c4b1084
change add in results
2018-06-20 12:38:41 +02:00
Sebdraven
e8aefde2ee
add logs
2018-06-20 12:36:32 +02:00
Sebdraven
7195f33f5d
correct error keys
2018-06-20 12:34:07 +02:00
Sebdraven
c14d05adef
test patries expansion
2018-06-20 12:32:54 +02:00
Sebdraven
8ae7210aef
add onyphe full module
2018-06-20 11:07:33 +02:00
Sebdraven
023c35f5d8
add onyphe full module and code the stub
2018-06-14 16:47:11 +02:00
Sebdraven
14695bbeb9
correct codecov
2018-06-11 13:34:45 +02:00
Sebdraven
755d907580
pep 8 compliant
2018-06-11 13:21:21 +02:00
Sebdraven
f6b8655f64
correct type of comments
2018-06-11 12:29:51 +02:00
Sebdraven
43402fde26
correct typo
2018-06-11 12:28:40 +02:00
Sebdraven
e0631c9651
correct typo
2018-06-11 12:02:34 +02:00
Sebdraven
59b49f9d20
add domains forward
2018-06-11 12:00:46 +02:00
Sebdraven
d9ee5286e3
add domains
2018-06-11 11:59:00 +02:00
Sebdraven
2e0e63fad6
add targeting os
2018-06-11 11:25:17 +02:00
Sebdraven
7580c63433
add category for AS number
2018-06-11 10:59:06 +02:00
Sebdraven
f069cd9bf4
change keys
2018-06-11 10:56:40 +02:00
Sebdraven
0a543ca0d5
change type
2018-06-11 10:55:44 +02:00
Sebdraven
ef035d051b
add category
2018-06-11 10:54:06 +02:00
Sebdraven
735e626058
add as number with onyphe
2018-06-11 10:41:05 +02:00
Sebdraven
04032d110c
add as number with onyphe
2018-06-08 18:31:08 +02:00
Sebdraven
cad35b5332
error indentation
2018-06-08 18:11:04 +02:00
Sebdraven
3ec1535897
correct key in map result
2018-06-08 18:09:59 +02:00
Sebdraven
f18f8fe05a
correct a bug
2018-06-08 18:01:58 +02:00
Sebdraven
6eeca0fba1
add pastebin url imports
2018-06-08 17:53:50 +02:00
Sebdraven
e6bac113ba
add onyphe module
2018-06-08 16:38:41 +02:00
Andras Iklody
0b0f57b30c
Update countrycode.py
2018-06-06 08:31:41 +02:00
Alexandre Dulaunoy
2d9b0cd172
Merge branch 'master' of github.com:MISP/misp-modules
2018-05-29 21:59:25 +02:00
Alexandre Dulaunoy
9664127b85
add: new expansion module to check hashes against hashdd.com including NSLR dataset.
2018-05-29 21:54:22 +02:00
chrisr3d
2b509a2fd3
Updated delimiter finder function
2018-05-18 11:38:13 +02:00
chrisr3d
1fb72f3c7a
add: Added user config to specify if there is a header in the csv to import
2018-05-18 11:33:53 +02:00
chrisr3d
dba8bd8c5b
fix: Avoid trying to build attributes with not intended fields
...
- Previously: if the header field is not an attribute type, then
it was added as an attribute field.
PyMISP then used to skip it if needed
- Now: Those fields are discarded before they are put in an attribute
2018-05-17 16:24:11 +02:00
chrisr3d
c088b13f03
fix: Using userConfig to define the header instead of moduleconfig
2018-05-17 13:47:49 +02:00
Christophe Vandeplas
0593dbb408
ta import - more filter for pollution
2018-05-16 11:50:47 +02:00
Christophe Vandeplas
67cecc89d0
threatanalyzer_import - minor generic noise removal
2018-05-15 13:02:17 +02:00
Christophe Vandeplas
27a22e5d86
threatanalyzer_import - loads sample info + pollution fix
2018-05-03 09:42:38 +02:00
Christophe Vandeplas
370011c081
threatanalyzer_import - fix regkey issue
2018-05-02 12:43:34 +02:00
Nick Driver
252d190714
fix missing comma
...
fix ip-dst and vulnerability input
2018-03-30 14:27:37 -04:00
Koen Van Impe
6d23d4f4c7
Fix VMRay API access error
...
hotfix for the "Unable to access VMRay API" error
2018-03-30 15:11:25 +02:00
Fred Morris
d0f618b648
Add exception blocks for query errors.
2018-03-08 15:26:39 -08:00
x41\x43
0436118747
Improving regex (validating e-mail)
...
Line 48:
The previous regex ` ^[\w\.\+\-]+\@[\w]+\.[a-z]{2,3}$ ` matched only a small subset of valid e-mail address (e.g.: didn't match domain names longer than 3 chars or user@this-domain.de or user@multiple.level.dom ) and needed to be with start (^) and end ($).
This ` [a-zA-Z0-9!#$%&'*+\/=?^_`{|}~-]+(?:\.[a-zA-Z0-9!#$%&'*+\/=?^_`{|}~-]+)*@(?:[a-zA-Z0-9](?:[a-zA-Z0-9-]*[a-zA-Z0-9])?\.)+[a-zA-Z0-9](?:[a-zA-Z0-9-]*[a-zA-Z0-9])? ` is not perfect (e.g: can't match oriental chars), but imho is much more complete.
Regex tested with several e-mail addresses with Python 3.6.4 and Python 2.7.14 on Linux 4.14.
2018-03-06 18:12:36 +01:00
chrisr3d
d885286792
Clarified functions arguments using a class
2018-03-05 19:59:30 +01:00
chrisr3d
4d7642ac91
add: Added Object References in the objects imported
2018-03-05 14:58:31 +01:00
chrisr3d
82fe8ba78c
fix: Fixed input & output of the module
2018-03-02 11:03:21 +01:00
chrisr3d
70436b7ddb
Merge branch 'csvimport' of github.com:chrisr3d/misp-modules into goaml
2018-03-02 09:40:46 +01:00
chrisr3d
c9ef578262
Removed print
2018-03-02 09:09:12 +01:00
chrisr3d
8d345d8cf5
Merge branch 'master' of github.com:MISP/misp-modules into csvimport
2018-03-02 09:05:46 +01:00
chrisr3d
e6c55f5dde
fix: Fixed input & output of the module
...
Also updated some functions
2018-03-02 09:03:51 +01:00
chrisr3d
03d20856d9
add: added goamlimport
2018-02-28 22:46:39 +01:00
chrisr3d
323f71cdd3
Fixed some details about the module output
2018-02-28 17:41:45 +01:00
chrisr3d
8f5c08e2c6
Converting GoAML into MISPEvent
2018-02-28 15:07:55 +01:00
chrisr3d
cad62464c5
Now parsing all the transaction attributes
2018-02-27 11:08:37 +01:00
chrisr3d
a02dbd6a8d
fix: Fixed typo of the aml type for country codes
2018-02-26 18:52:28 +01:00
chrisr3d
478cd53912
add: Added dictionary to map aml types into MISP types
2018-02-26 18:13:43 +01:00
chrisr3d
5df2d309a0
typo
2018-02-26 15:58:53 +01:00
chrisr3d
81a6be17d3
chg: Structurded data
2018-02-26 11:47:35 +01:00
chrisr3d
359ac9100e
fix: typo in references mapping dictionary
2018-02-23 15:58:04 +01:00
Christian Studer
983b7da7b7
fix: Added an object checking
...
- Checking if there are objects in the event, and then if there is at least 1 transaction object
- This prevents the module from crashing, but does not guaranty having a valid GoAML file (depending on objects and their relations)
2018-02-22 16:55:52 +01:00
chrisr3d
b2b0fccd47
fix: Added an object checking
...
- Checking if there are objects in the event, and then
if there is at least 1 transaction object
- This prevents the module from crashing, but does not
guaranty having a valid GoAML file (depending on
objects and their relations)
2018-02-22 16:37:27 +01:00
chrisr3d
53b4a43448
Merge branch 'master' of github.com:chrisr3d/misp-modules into aml_import
2018-02-22 14:29:36 +01:00
chrisr3d
c942013812
chg: Modified the mapping dictionary to support misp-objects updates
2018-02-22 01:23:08 +01:00
chrisr3d
5995458aab
fix: Added the moduleinfo field need to have MISP event in standard format
2018-02-21 17:14:26 +01:00
Alexandre Dulaunoy
c3ac53a069
fix: goamlexport added
2018-02-20 17:18:36 +01:00
chrisr3d
f361fb4ee3
Reading the entire document, to create a big dictionary containing the data, as a beginning
2018-02-20 17:00:13 +01:00
chrisr3d
02b8938b2a
typo
2018-02-20 16:57:27 +01:00
chrisr3d
11dddb974b
Merge branch 'master' of github.com:MISP/misp-modules
2018-02-20 15:18:45 +01:00