Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MISP WarningLists CIDR notation support #197

Closed
srilumpa opened this issue Feb 22, 2018 · 1 comment
Closed

MISP WarningLists CIDR notation support #197

srilumpa opened this issue Feb 22, 2018 · 1 comment
Labels
category:enhancement Issue is related to an existing feature to improve scope:analyzer Issue is analyzer related

Comments

@srilumpa
Copy link
Contributor

Request Type

Bug / Feature

Work Environment

Question Answer
OS version (server) Debian
Cortex Analyzer Name MISPWarningLists
Cortex Analyzer Version 1.0
Cortex Version 1.1.4

Description

Some data shipped by the MISP WarningLists project are IP ranges registered through their CIDR notation. The analyzer is not able to properly check if an IP address is included in those ranges.

Steps to Reproduce

  1. Analyze the IP address 139.217.32.10 (included in the 139.217.32.0/24 range from the microsoft-office365-cn list when this issue is registered)
  2. The analyzer outputs "No hits"

Possible Solutions

@3c7 3c7 added category:enhancement Issue is related to an existing feature to improve scope:analyzer Issue is analyzer related labels Apr 6, 2018
@3c7
Copy link
Contributor

3c7 commented Oct 17, 2018

Already merged. Thanks again, @srilumpa.

@3c7 3c7 closed this as completed Oct 17, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:enhancement Issue is related to an existing feature to improve scope:analyzer Issue is analyzer related
Projects
None yet
Development

No branches or pull requests

2 participants