mirror of
https://github.com/valitydev/Cortex-Analyzers.git
synced 2024-11-06 09:05:19 +00:00
#873 minemeld
This commit is contained in:
parent
c9722aabad
commit
4de696c9b0
14
responders/Minemeld/README.md
Normal file
14
responders/Minemeld/README.md
Normal file
@ -0,0 +1,14 @@
|
|||||||
|
### Palo Alto Minemeld
|
||||||
|
|
||||||
|
This responder sends observables you select to a [Palo Alto Minemeld](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/minemeld) instance.
|
||||||
|
|
||||||
|
#### Requirements
|
||||||
|
The following options are required in the Palo Alto Minemeld Responder configuration:
|
||||||
|
|
||||||
|
- `minemeld_url` : URL of the Minemeld instance to which you will be posting indicators
|
||||||
|
- `minemeld_user`: user accessing the Minemeld instance
|
||||||
|
- `minemeld_password`: password for the user accessing the Minemeld instance
|
||||||
|
- `minemeld_indicator_list`: name of Minemeld indicator list (already created in Minemeld)
|
||||||
|
- `minemeld_share_level`: share level for indicators (defaults to `red`)
|
||||||
|
- `minemeld_confidence`: confidence level for indicators (defaults to `100`)
|
||||||
|
- `minemeld_ttl`: TTL for indicators (defaults to `86400` seconds)
|
BIN
responders/Minemeld/assets/MM-logo.png
Normal file
BIN
responders/Minemeld/assets/MM-logo.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 2.4 KiB |
@ -1,69 +1,85 @@
|
|||||||
{
|
{
|
||||||
"name": "Minemeld",
|
"name": "Minemeld",
|
||||||
"version": "1.0",
|
"version": "1.0",
|
||||||
"author": "Wes Lambert, Security Onion Solutions",
|
"author": "Wes Lambert, Security Onion Solutions",
|
||||||
"url": "https://github.com/TheHive-Project/Cortex-Analyzers",
|
"url": "https://github.com/TheHive-Project/Cortex-Analyzers",
|
||||||
"license": "AGPL-V3",
|
"license": "AGPL-V3",
|
||||||
"description": "Submit indicator to Minemeld",
|
"description": "Submit indicator to Minemeld",
|
||||||
"dataTypeList": ["thehive:case_artifact"],
|
"dataTypeList": [
|
||||||
"command": "Minemeld/minemeld.py",
|
"thehive:case_artifact"
|
||||||
"baseConfig": "Minemeld",
|
],
|
||||||
"configurationItems": [
|
"command": "Minemeld/minemeld.py",
|
||||||
{
|
"baseConfig": "Minemeld",
|
||||||
"name": "minemeld_url",
|
"configurationItems": [
|
||||||
"description": "URL for Minemeld instance",
|
{
|
||||||
"type": "string",
|
"name": "minemeld_url",
|
||||||
"multi": false,
|
"description": "URL for Minemeld instance",
|
||||||
"required": true,
|
"type": "string",
|
||||||
"defaultValue": "https://x.x.x.x"
|
"multi": false,
|
||||||
|
"required": true,
|
||||||
|
"defaultValue": "https://x.x.x.x"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "minemeld_user",
|
||||||
|
"description": "User for Minemeld",
|
||||||
|
"type": "string",
|
||||||
|
"multi": false,
|
||||||
|
"required": true,
|
||||||
|
"defaultValue": "apiuser"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "minemeld_password",
|
||||||
|
"description": "Password for Minemeld",
|
||||||
|
"type": "string",
|
||||||
|
"multi": false,
|
||||||
|
"required": true,
|
||||||
|
"defaultValue": "password"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "minemeld_indicator_list",
|
||||||
|
"description": "Name of indicator list to which indicators will be added",
|
||||||
|
"type": "string",
|
||||||
|
"multi": false,
|
||||||
|
"required": true,
|
||||||
|
"defaultValue": "my_block_list"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "minemeld_share_level",
|
||||||
|
"description": "Share level for indicator",
|
||||||
|
"type": "string",
|
||||||
|
"multi": false,
|
||||||
|
"required": true,
|
||||||
|
"defaultValue": "red"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "minemeld_confidence",
|
||||||
|
"description": "Confidence level for indicator",
|
||||||
|
"type": "string",
|
||||||
|
"multi": false,
|
||||||
|
"required": true,
|
||||||
|
"defaultValue": "100"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "minemeld_ttl",
|
||||||
|
"description": "TTL for indicator",
|
||||||
|
"type": "string",
|
||||||
|
"multi": false,
|
||||||
|
"required": true,
|
||||||
|
"defaultValue": "86400"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"registration_required": false,
|
||||||
|
"subscription_required": false,
|
||||||
|
"free_subscription": false,
|
||||||
|
"service_homepage": "https://github.com/PaloAltoNetworks/minemeld",
|
||||||
|
"service_logo": {
|
||||||
|
"path": "assets/MM-logo.png",
|
||||||
|
"caption": "logo"
|
||||||
},
|
},
|
||||||
{
|
"screenshots": [
|
||||||
"name": "minemeld_user",
|
{
|
||||||
"description": "User for Minemeld",
|
"path": "",
|
||||||
"type": "string",
|
"caption": ""
|
||||||
"multi": false,
|
}
|
||||||
"required": true,
|
]
|
||||||
"defaultValue": "apiuser"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "minemeld_password",
|
|
||||||
"description": "Password for Minemeld",
|
|
||||||
"type": "string",
|
|
||||||
"multi": false,
|
|
||||||
"required": true,
|
|
||||||
"defaultValue": "password"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "minemeld_indicator_list",
|
|
||||||
"description": "Name of indicator list to which indicators will be added",
|
|
||||||
"type": "string",
|
|
||||||
"multi": false,
|
|
||||||
"required": true,
|
|
||||||
"defaultValue": "my_block_list"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "minemeld_share_level",
|
|
||||||
"description": "Share level for indicator",
|
|
||||||
"type": "string",
|
|
||||||
"multi": false,
|
|
||||||
"required": true,
|
|
||||||
"defaultValue": "red"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "minemeld_confidence",
|
|
||||||
"description": "Confidence level for indicator",
|
|
||||||
"type": "string",
|
|
||||||
"multi": false,
|
|
||||||
"required": true,
|
|
||||||
"defaultValue": "100"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "minemeld_ttl",
|
|
||||||
"description": "TTL for indicator",
|
|
||||||
"type": "string",
|
|
||||||
"multi": false,
|
|
||||||
"required": true,
|
|
||||||
"defaultValue": "86400"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
}
|
Loading…
Reference in New Issue
Block a user