Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FR] New Analyzer: Palo Alto Wildfire Sandbox #910

Closed
nachorpaez opened this issue Nov 29, 2020 · 2 comments · Fixed by #1094
Closed

[FR] New Analyzer: Palo Alto Wildfire Sandbox #910

nachorpaez opened this issue Nov 29, 2020 · 2 comments · Fixed by #1094

Comments

@nachorpaez
Copy link
Contributor

Feature description
Query Wildfire Public API to get detailed information about an URL or file.
Analyzer will require valid Wildfire subscription.

Will support the following data types:

  • File
  • Hash
  • URL

Describe the solution you'd like
This analyzer will allow you to submit URL's and files to Wildfire sandbox. Also it will allow analysts to query for verdict and detailed report of URL and hashes.

Additional context
Will use the Palo Alto API for Wildfire https://docs.paloaltonetworks.com/wildfire/u-v/wildfire-api

@nachorpaez
Copy link
Contributor Author

Managed to create the analyzer but got a bit lost on getting the best way to show all the information on the reporting template.

Won't be able to keep working on this because I no longer have access to a Wildfire subscription.

Pushed all my code in my fork in case someone wants to keep working on it.

@joeslazaro-cdw
Copy link
Contributor

joeslazaro-cdw commented May 26, 2022

I've got the analyzer and report working perfectly and I'll be submitting a PR to the main repository soon.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants