Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add more Lookup providers and file hashes #25

Open
ion-storm opened this issue Mar 2, 2017 · 8 comments
Open

Add more Lookup providers and file hashes #25

ion-storm opened this issue Mar 2, 2017 · 8 comments

Comments

@ion-storm
Copy link

Please add the following IOC's and lookups, I'd like to use Sysmon Hash checks as well:
IPv4
MD5
SHA1
SHA256
CVE
FQDN (EFQDN is for Internet FQDN, IFQDN is for internal domains)

ThreatMiner for IPv4, FQDN, MD5, SHA1 and SHA2 lookups.
Alienvault OTX for IPv4, MD5, SHA1 and SHA2 lookups.
IBM X-Force Exchange for IPv4, EFQDN lookups.
VirusTotal for MD5, SHA1, SHA2 and FQDN lookups.
Cymon.io for IPv4 lookups.
CIRCL (Computer Incident Response Center Luxembourg) for CVE lookups.
PassiveTotal for FQDN Whois lookups
MISP for MD5 and SHA2 (If you want more submit an issue in this github)
Censys.io for IPv4 lookups
Shodan for IPV4 lookups

@ion-storm
Copy link
Author

Basically same features as threat pinch implemented into Graylog threat Intel. Also I'd like to add malware domains lists as well

@joschi joschi added the feature label Mar 2, 2017
@joschi joschi changed the title Feature Request: Add more Lookup providers and file hashes Add more Lookup providers and file hashes Mar 2, 2017
@lennartkoopmann
Copy link
Contributor

We'll start looking into this really soon!

@kurobeats
Copy link

Emerging threats pulls from hereL

http://www.openbl.org/lists/base.txt

@lennartkoopmann lennartkoopmann added this to the 1.0 milestone Mar 25, 2017
@joschi joschi removed this from the 1.0 milestone Sep 26, 2017
@fulldanad
Copy link

fulldanad commented Mar 15, 2018

Hi Gents,

Sounds good to have a generic lookup feature for log enrichment in particular for otx, virustotal and misp hashes. 👍

Find below some additionnal free sources I'd like to use to enrich my logs with :

http://rules.emergingthreats.net/blockrules
http://rules.emergingthreats.net/fwrules
http://hailataxii.com
https://www.iblocklist.com/lists
http://mirror1.malwaredomains.com
https://www.phishtank.com/
https://isc.sans.edu/suspicious_domains.html

Cheers

@ion-storm
Copy link
Author

I have Graylog parse and add an MD5 field for each file executed on windows systems, can we add MD5 file checking:

OTX already support MD5/SHA256/imphash lookup:
example:
https://otx.alienvault.com/indicator/file/db349b97c37d22f5ea1d1841e3c89eb4

API Examples:
https://otx.alienvault.com/static/external_api.html#panel_api_v1_indicators_file__file_hash___section_

@skear
Copy link

skear commented Nov 16, 2018

VirusTotal file hash lookups would be very useful for use in combination with messages received from sysmon.

@dio99
Copy link

dio99 commented Jun 11, 2020

how is this going ? will it be added soon ?

@MP-blue
Copy link

MP-blue commented Jul 30, 2020

The current options of TOR, abuse.ch (seems to be discontinued: https://ransomwaretracker.abuse.ch/) and Spamhaus are just not enough these days. AFAIK AlienVault's OTX isn't part of the Threat Intel Plugin any longer.

Additional integrations are badly needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

9 participants