[MontySecurity C2 Tracker] Add montysecurity C2-Tracker connector #3318
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Proposed changes
Checklist
Further comments
This commit contains a purge.py script that is not automatically used under any circumstance but may be useful to the operator in order to delete all IOCs from this IOC feed.
The Dockerfile uses harcoded values for they pycti and request library versions. The current version of pycti breaks a part of this connector so it has been backdated for the docker image.
The IOCs are pulled from https://github.com/montysecurity/C2-Tracker
Connector.py automatically prunes IOCs, uses labels to prevent interfering with other IOCs.
Contains functionality to link IOCs to entities created by the MITRE Connector. This functionality does not require extra setup by the operator.