Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VMRay: add artifact extraction, more taxonomies and report details #802

Closed

Conversation

mback2k
Copy link
Contributor

@mback2k mback2k commented Jun 22, 2020

Rework the VMRay analyzer to extract artifacts (based on IOCs identified by VMRay), create more taxonomies (based upon Threat Indicators by VMRay) and include more report details (analysis results).

This is just a draft PR to have CI and publish the WIP changes for now. Please do not merge yet.

@53A-1 53A-1 mentioned this pull request Jun 26, 2020
@mback2k
Copy link
Contributor Author

mback2k commented Jul 6, 2020

@jeromeleonard please take a look #807 (comment).

mback2k pushed a commit to TKCERT/Cortex-Analyzers that referenced this pull request Jul 7, 2020
• Adding support for URL submissions
• Simplified API error handling
• Inverted reanalysis enablement logic (getting rid of negation)
• Improving artifact extraction
• Improving taxonomy creation
• Implemented recursion of samples (relations) and limits on it
• Adding config value for polling interval
• Adding support for archives with passwords
• Adding support for different archive modes (compound and separate)
• Formatting code using black (https://github.com/psf/black)
• TheHive short report template: Using div instead of span to
prevent overflow

**
Based on
TheHive-Project#802
by https://github.com/mback2k
mback2k pushed a commit to TKCERT/Cortex-Analyzers that referenced this pull request Jul 24, 2020
• Adding support for URL submissions
• Simplified API error handling
• Inverted reanalysis enablement logic (getting rid of negation)
• Improving artifact extraction
• Improving taxonomy creation
• Implemented recursion of samples (relations) and limits on it
• Adding config value for polling interval
• Adding support for archives with passwords
• Adding support for different archive modes (compound and separate)
• Formatting code using black (https://github.com/psf/black)
• TheHive short report template:
  Using div instead of span to prevent overflow

**
Based on
TheHive-Project#802
by https://github.com/mback2k
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants