Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] FalconCustomIOC responder Not working #904

Open
tunisia-team opened this issue Nov 17, 2020 · 2 comments
Open

[Bug] FalconCustomIOC responder Not working #904

tunisia-team opened this issue Nov 17, 2020 · 2 comments
Labels
category:bug Issue is related to a bug help wanted scope:responder Issues/PRs pertaining to responders

Comments

@tunisia-team
Copy link

Describe the bug
Installing FalconCustomIOC responder and configure it by adding the Client ID and secret key in Cortex.
When executing the responder from TheHive, there isn't any result shows and shows failed as result

To Reproduce
Steps to reproduce the behavior:

  1. Configure FalconCustomIOC responder by adding the Client ID and secret key in Cortex GUI
  2. Go to an observable to theHive and run the responder

Expected behavior
The observable should be added to IOC list in CrowdStrike.

Complementary information
Error message in responder details:
"errorMessage": "Unexpected end-of-input within/between Object entries\n at [Source: (sun.nio.ch.ChannelInputStream); line: 1, column: 1257]"

Work environment

  • Client OS: Windows 10
  • Server OS: Linux
  • Browse type and version: Firefox
  • Cortex version: 3.0.0-1
  • Cortex Analyzer/Responder name: FalconCustomIOC
  • Cortex Analyzer/Responder version: 1.0

Possible solutions
If applicable, indicate possible solutions to the problem.

Additional context
Add any other context about the problem here.

@tunisia-team tunisia-team added the category:bug Issue is related to a bug label Nov 17, 2020
@jeromeleonard jeromeleonard added help wanted scope:responder Issues/PRs pertaining to responders labels Nov 18, 2020
@jeromeleonard
Copy link
Contributor

jeromeleonard commented Nov 18, 2020

Unfortunately we do not have any access to Falcon plateform.

@ag-michael can you help this issue please ?

Thank you,

@ag-michael
Copy link
Contributor

@tunisia-team I no longer have access to Falcon so my ability to support the responder is very limited at this time, I am looking for people that can help me with that. That said, if you can post a more complete log and redacted config file, I might be able to help.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:bug Issue is related to a bug help wanted scope:responder Issues/PRs pertaining to responders
Projects
None yet
Development

No branches or pull requests

3 participants