This commit is contained in:
Jérôme Leonard 2020-11-18 17:22:27 +01:00
parent c9722aabad
commit 4de696c9b0
3 changed files with 97 additions and 67 deletions

View File

@ -0,0 +1,14 @@
### Palo Alto Minemeld
This responder sends observables you select to a [Palo Alto Minemeld](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/minemeld) instance.
#### Requirements
The following options are required in the Palo Alto Minemeld Responder configuration:
- `minemeld_url` : URL of the Minemeld instance to which you will be posting indicators
- `minemeld_user`: user accessing the Minemeld instance
- `minemeld_password`: password for the user accessing the Minemeld instance
- `minemeld_indicator_list`: name of Minemeld indicator list (already created in Minemeld)
- `minemeld_share_level`: share level for indicators (defaults to `red`)
- `minemeld_confidence`: confidence level for indicators (defaults to `100`)
- `minemeld_ttl`: TTL for indicators (defaults to `86400` seconds)

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.4 KiB

View File

@ -1,69 +1,85 @@
{ {
"name": "Minemeld", "name": "Minemeld",
"version": "1.0", "version": "1.0",
"author": "Wes Lambert, Security Onion Solutions", "author": "Wes Lambert, Security Onion Solutions",
"url": "https://github.com/TheHive-Project/Cortex-Analyzers", "url": "https://github.com/TheHive-Project/Cortex-Analyzers",
"license": "AGPL-V3", "license": "AGPL-V3",
"description": "Submit indicator to Minemeld", "description": "Submit indicator to Minemeld",
"dataTypeList": ["thehive:case_artifact"], "dataTypeList": [
"command": "Minemeld/minemeld.py", "thehive:case_artifact"
"baseConfig": "Minemeld", ],
"configurationItems": [ "command": "Minemeld/minemeld.py",
{ "baseConfig": "Minemeld",
"name": "minemeld_url", "configurationItems": [
"description": "URL for Minemeld instance", {
"type": "string", "name": "minemeld_url",
"multi": false, "description": "URL for Minemeld instance",
"required": true, "type": "string",
"defaultValue": "https://x.x.x.x" "multi": false,
"required": true,
"defaultValue": "https://x.x.x.x"
},
{
"name": "minemeld_user",
"description": "User for Minemeld",
"type": "string",
"multi": false,
"required": true,
"defaultValue": "apiuser"
},
{
"name": "minemeld_password",
"description": "Password for Minemeld",
"type": "string",
"multi": false,
"required": true,
"defaultValue": "password"
},
{
"name": "minemeld_indicator_list",
"description": "Name of indicator list to which indicators will be added",
"type": "string",
"multi": false,
"required": true,
"defaultValue": "my_block_list"
},
{
"name": "minemeld_share_level",
"description": "Share level for indicator",
"type": "string",
"multi": false,
"required": true,
"defaultValue": "red"
},
{
"name": "minemeld_confidence",
"description": "Confidence level for indicator",
"type": "string",
"multi": false,
"required": true,
"defaultValue": "100"
},
{
"name": "minemeld_ttl",
"description": "TTL for indicator",
"type": "string",
"multi": false,
"required": true,
"defaultValue": "86400"
}
],
"registration_required": false,
"subscription_required": false,
"free_subscription": false,
"service_homepage": "https://github.com/PaloAltoNetworks/minemeld",
"service_logo": {
"path": "assets/MM-logo.png",
"caption": "logo"
}, },
{ "screenshots": [
"name": "minemeld_user", {
"description": "User for Minemeld", "path": "",
"type": "string", "caption": ""
"multi": false, }
"required": true, ]
"defaultValue": "apiuser" }
},
{
"name": "minemeld_password",
"description": "Password for Minemeld",
"type": "string",
"multi": false,
"required": true,
"defaultValue": "password"
},
{
"name": "minemeld_indicator_list",
"description": "Name of indicator list to which indicators will be added",
"type": "string",
"multi": false,
"required": true,
"defaultValue": "my_block_list"
},
{
"name": "minemeld_share_level",
"description": "Share level for indicator",
"type": "string",
"multi": false,
"required": true,
"defaultValue": "red"
},
{
"name": "minemeld_confidence",
"description": "Confidence level for indicator",
"type": "string",
"multi": false,
"required": true,
"defaultValue": "100"
},
{
"name": "minemeld_ttl",
"description": "TTL for indicator",
"type": "string",
"multi": false,
"required": true,
"defaultValue": "86400"
}
]
}