-
Notifications
You must be signed in to change notification settings - Fork 385
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
AbuseIPDB analyzer creation #353
Comments
Any updates? That would be a great addition. |
Sorry for coming late, I have just sent a pull request few moments ago #400 |
Oh shit... I was working on it :-/ |
@mlodic,
Do it works for you? Moreover, would it be relevant to play with the "abuseConfidenceScore" filed present in the output to improve the Analyzer's answer? |
@mlodic yes, I think that the logging statements is the reason why the analyzer output is not a valid json. |
I have just pushed a little change to improve error handling cases, tell me if it's better now. About the "abuseConfidenceScore", I think that it should not change the "summary" result in any way. You risk to miss interesting reports if you set a threshold. Most people who send reports to AbuseIPDB does not move that score at all. |
I'm sorry, I can't see any change. Thanks for your feedback, |
I don't know where you get that hash, go through this pull request #400 |
I directly went to the forked repository: However, using the PR #400 (here) I still have the same issue:
Let me know if you need additinal tests! |
My commits are in the "develop" branch, not in the "master", that was the cause you didn't reach changes. Could you provide some context on your error message, because on my side I cannot replicate your issue. Try/except clauses should manage all cases. If you can, try this commit |
OK, I'll try this change: https://github.com/TheHive-Project/Cortex-Analyzers/tree/a20ce52f683acd67705743c13aca431944a40c81/analyzers/AbuseIPDB and I let you know. |
Dear,
It works! Thanks and congratulations... |
Thanks for your help! |
@nadouani Any chance to add this new analyzer to the existing ones? |
template is ready, see #425 |
Request Type
Analyzer
Description
AbuseIPDB analyzer to determine whether an IP was reported or not as malicious by AbuseIPDB -> https://www.abuseipdb.com/
Possible Solutions
I'm working on the creation of the analyzer
The text was updated successfully, but these errors were encountered: