Comments (14)
I'm on it!
from pymisp.
thanks :)
from pymisp.
I wanted to compare the changes you made, can you please revert the change from spaces to tab, please? it makes it very hard to review.
Just to make sure we're talking bout the same thing: you made changes in the openioc library, and it isn't reflected in the misp-modules, but works properly when you dump the json from the library?
Did you make sure you installed the pymisp version containing your changes? Because the misp-modules openioc module is picking the output of the openioc library as-is: https://github.com/MISP/misp-modules/blob/master/misp_modules/modules/import_mod/openiocimport.py#L56
from pymisp.
Done
from pymisp.
ha ok :(
I don't merge misp-modules ...
all my bad :(
I work with multiple instance sorry again
from pymisp.
from pymisp.
\o/ Looks great.
Just one thing: are you sure you want to use "External Analysis" as category? This is an information you can pass as a tag for example. I'd recommend to use the default sane values set by the server for each types
from pymisp.
I thinks "External Analysis" is maybe the good category because when you import an ioc it often comes from an external analysis. No ?
Can I add some tag on attribut when I import an ioc.
The idea is to define in "userConfig" or in "moduleconfig" a "tag by default" (ex : tlp:white).
But I do not think that misp can take it into account on its side.
from pymisp.
Well, not necessarily: it can come from an internal tool and be push into MISP.
We generally recommend to use "External Analysis" for a few attributes in an event (for example the link to the external analysis).
from pymisp.
And suddenly what are you recommend ?
Next, I make change and do the pull/request
from pymisp.
Not sure I get your question. The recommended values per type are here: https://github.com/MISP/PyMISP/blob/master/pymisp/data/describeTypes.json But you don't need to care, they are set automatically by the server.
from pymisp.
Not sure I get your question. For default tag ?
Otherwise ok, I will remove the category :)
from pymisp.
Thanks Raphaël,
You can close this issue. I have make the request #82
I think I open a new issue to add possibility to set default tag when you import something with module.
from pymisp.
Excellent, thanks!
from pymisp.
Related Issues (20)
- assigning tags to attributes older than 'x' days HOT 1
- Adding mail flag to stats_report.py results in Unicode error HOT 1
- Complex Build Query TAG parameter not working
- EventSearch returns all events HOT 1
- PyMISP.search does not include events with 0 attributes HOT 3
- Bug: Could not add object due to incomplete attribute value "malware-sample" in FileObject HOT 1
- Return value does not respect the parameter `expanded=True` HOT 1
- Requirement of a new MISP object
- Bug: `update_event()` with `add_event_report()` doesn't add a report to existing Event HOT 5
- Enhancement: PyMISP API Custom HTTPS Adapters HOT 1
- Remove test files containing malicious objects HOT 1
- Bug - Exported event schema validation fails HOT 10
- Error code 403 over remote event update using only local tags HOT 11
- PyMISP.search does not allow searching for attributes with first_seen as None HOT 3
- Issue with Adding a Tag to Event via PyMISP HOT 5
- Email parsing for email-body attribute is broken from PyMISP v2.4.184 to v2.4.184.2 HOT 4
- AttributeError: module 'pymisp' has no attribute 'EmailObject' when doing from pymisp import * HOT 2
- PyMISP.toggle_warninglist() sends GET method HOT 4
- PyMISP.disable_warninglist() doesn't disable, but toggle instead HOT 1
- Is it possible to change the timestamp for an attribute programatically? HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from pymisp.