Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cisco Umbrella Blacklister Responder #382

Closed
arnydo opened this issue Nov 30, 2018 · 5 comments
Closed

Cisco Umbrella Blacklister Responder #382

arnydo opened this issue Nov 30, 2018 · 5 comments
Labels
scope:responder Issues/PRs pertaining to responders
Milestone

Comments

@arnydo
Copy link
Contributor

arnydo commented Nov 30, 2018

Request Type

Responder

Description

Responder will allow the blacklisting of a domain in Cisco Umbrella utilizing the Enforcement API.

Possible Solutions

I'm working on the creation of the responder.

@nadouani nadouani added status:in progress scope:responder Issues/PRs pertaining to responders labels Nov 30, 2018
@arnydo
Copy link
Contributor Author

arnydo commented Nov 30, 2018

I am attempting to have the responder available for domain observables. I assume the configuration is the same as an analyzer. Is there something I am missing? The responder is not available when using TheHive.

"dataType": "domain",

image

@nadouani
Copy link
Contributor

Hello, Responders are not like analyzers and can run against cases, tasks, observables, logs and alerts.

You can find the list at: https://github.com/TheHive-Project/CortexDocs/blob/master/api/how-to-create-a-responder.md#datatypelist

@arnydo
Copy link
Contributor Author

arnydo commented Nov 30, 2018

@nadouani Thank you for clarifying. I missed that page of the docs...

I have it working now.

Ideally, I would like to have the option to add a tag to the artifact showing that it has been blacklisted in Umbrella. Is there any ETA on adding the operation "AddTagToArtifact"? Should I go ahead and create a PR without it or wait until this is available?

UmbrellaBlacklister

@arnydo
Copy link
Contributor Author

arnydo commented Nov 30, 2018

Please disregard last comment. Found that "AddTagToArtifact" is available; it just was not listed in the documentation. I created a PR for that change in CortexDocs.

Created PR for this: #383

@nadouani nadouani added this to the 1.15.0 milestone Dec 4, 2018
@nadouani
Copy link
Contributor

nadouani commented Dec 4, 2018

PR accepted

@nadouani nadouani closed this as completed Dec 4, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
scope:responder Issues/PRs pertaining to responders
Projects
None yet
Development

No branches or pull requests

2 participants