Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proofpoint Forensics Lookup #117

Closed
typonino opened this issue Oct 23, 2017 · 8 comments
Closed

Proofpoint Forensics Lookup #117

typonino opened this issue Oct 23, 2017 · 8 comments
Labels
category:feature-request Issue is related to a feature request scope:analyzer Issue is analyzer related status:merged status:pr-submitted
Milestone

Comments

@typonino
Copy link
Contributor

typonino commented Oct 23, 2017

Request Type

Analyzer

Description

Hello,
I have created an analyzer for Proofpoint Forensics lookup. Proofpoint API is available to proofpoint customers and allows for searching url, file, or hash.
This cortex analyzer allows to search for known ioc against proofpoint forensics.

Possible Solutions

proofpoint forensics description: https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/Forensics_API

@saadkadhi
Copy link
Contributor

Hi @typonino. Thank you for this new contribution. Can you please submit a PR for the analyzer (or analyzers/analyzer flavors if you separated file analysis from URL/hash) against develop so we can review it and add it to the repo?

@saadkadhi saadkadhi added scope:analyzer Issue is analyzer related category:feature-request Issue is related to a feature request status:in progress labels Oct 25, 2017
@typonino
Copy link
Contributor Author

hello Saad,
I have added new pull Request "Proofpoint Threat Insight Lookup #120" based on dev branch.
Let me know if it's ok like this.

Regards,

@nadouani
Copy link
Contributor

nadouani commented Oct 26, 2017

Hello @typonino I think that you deleted the PR (#120)

@typonino
Copy link
Contributor Author

Hello @nadouani ,

i'm newbie in github. I have tried to create different branch for different analyzers.
I have removed and create new branch for each analyzer.
For this one, you can find the information here

When creating pull request, it is sent to my repo not yours. I think i have still missed a step again :)
If you can help me on this, i would appreicate !

Regards,

@nadouani
Copy link
Contributor

OK, you need to submit the PR again on the main Cortex-Analyzers repository.

Note that we are notified for any submitted PR, or comment on any issue, so we are aware of the cool stuff people contribute ;)

Thanks

@nadouani
Copy link
Contributor

@typonino
Copy link
Contributor Author

typonino commented Oct 26, 2017

I get it ! thank you :)

associated pull request is #123

@3c7
Copy link
Contributor

3c7 commented Oct 17, 2018

Thanks @typonino!

@3c7 3c7 closed this as completed Oct 17, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:feature-request Issue is related to a feature request scope:analyzer Issue is analyzer related status:merged status:pr-submitted
Projects
None yet
Development

No branches or pull requests

4 participants