-
Notifications
You must be signed in to change notification settings - Fork 385
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Analyzers: domain vs fqdn #350
Comments
There is also URLs to consider too. FYI, the Fortiguard plugin was fixed with #358 |
Hello @garanews I've just spotted this one. Can you list all the analyzers that need to be updated to include FQDN as possible datatype? We can add them to this issue's description as checklist and fix them. |
Hello @nadouani , I think all analyzers that have "domain" but not fqdn: Abuse_Finder Here you can see the full matrix: For everyone would generate this table, here there is the code (need python 3.5+, pandas, glob): |
Request Type
Question
Description
Analyzing attributes with datatype "hostname" and "domain" in MISP:
domain
data:image/s3,"s3://crabby-images/04b43/04b43360fd67d6dcb4b0242d566996ec3d816d1c" alt="image"
Page 1 of 1615, showing 60 records out of 96849 total, starting on record 1, ending on 60
hostname
data:image/s3,"s3://crabby-images/24e4c/24e4c95d2e49d7a589ff46a6b1bc45b0c6f56d52" alt="image"
Page 1 of 1393, showing 60 records out of 83522 total, starting on record 1, ending on 60
when imported in The Hive they become type "fqdn" and "domain".
In this situation the analyzers available for the 2 types are different:
But all the fqdn above mentioned can be analyzed with (almost?) all analyzers used for domain type.
Possible Solutions
In order to access to other analyzers (VT,etc), analyst is removing manually all fqdn imported and adds again as domain...
An option would be configure the "domain" analyzers to analyze also fqdn type.
What do you think?
The text was updated successfully, but these errors were encountered: