Git Product home page Git Product logo

Comments (14)

Rafiot avatar Rafiot commented on July 24, 2024

I'm on it!

from pymisp.

truckydev avatar truckydev commented on July 24, 2024

thanks :)

from pymisp.

Rafiot avatar Rafiot commented on July 24, 2024

I wanted to compare the changes you made, can you please revert the change from spaces to tab, please? it makes it very hard to review.

Just to make sure we're talking bout the same thing: you made changes in the openioc library, and it isn't reflected in the misp-modules, but works properly when you dump the json from the library?

Did you make sure you installed the pymisp version containing your changes? Because the misp-modules openioc module is picking the output of the openioc library as-is: https://github.com/MISP/misp-modules/blob/master/misp_modules/modules/import_mod/openiocimport.py#L56

from pymisp.

truckydev avatar truckydev commented on July 24, 2024

Done

from pymisp.

truckydev avatar truckydev commented on July 24, 2024

ha ok :(
I don't merge misp-modules ...

all my bad :(
I work with multiple instance sorry again

from pymisp.

truckydev avatar truckydev commented on July 24, 2024

probleme import ioc ok

from pymisp.

Rafiot avatar Rafiot commented on July 24, 2024

\o/ Looks great.

Just one thing: are you sure you want to use "External Analysis" as category? This is an information you can pass as a tag for example. I'd recommend to use the default sane values set by the server for each types

from pymisp.

truckydev avatar truckydev commented on July 24, 2024

I thinks "External Analysis" is maybe the good category because when you import an ioc it often comes from an external analysis. No ?

Can I add some tag on attribut when I import an ioc.
The idea is to define in "userConfig" or in "moduleconfig" a "tag by default" (ex : tlp:white).
But I do not think that misp can take it into account on its side.

from pymisp.

Rafiot avatar Rafiot commented on July 24, 2024

Well, not necessarily: it can come from an internal tool and be push into MISP.

We generally recommend to use "External Analysis" for a few attributes in an event (for example the link to the external analysis).

from pymisp.

truckydev avatar truckydev commented on July 24, 2024

And suddenly what are you recommend ?

Next, I make change and do the pull/request

from pymisp.

Rafiot avatar Rafiot commented on July 24, 2024

Not sure I get your question. The recommended values per type are here: https://github.com/MISP/PyMISP/blob/master/pymisp/data/describeTypes.json But you don't need to care, they are set automatically by the server.

from pymisp.

truckydev avatar truckydev commented on July 24, 2024

Not sure I get your question. For default tag ?

Otherwise ok, I will remove the category :)

from pymisp.

truckydev avatar truckydev commented on July 24, 2024

Thanks Raphaël,

You can close this issue. I have make the request #82

I think I open a new issue to add possibility to set default tag when you import something with module.

from pymisp.

Rafiot avatar Rafiot commented on July 24, 2024

Excellent, thanks!

from pymisp.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.