Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

adding Clam Analyzer #312

Closed
wants to merge 1 commit into from

Conversation

Hestat
Copy link

@Hestat Hestat commented Jul 24, 2018

Pull request for issue:
ClamAV New analyzer #311

ClamAV has become a very useful open source AV and general purpose scanner. I find it most useful in being able to parse Yara rules and the inclusion of sigtool to create your own Clam rule sets.

While I run this locally on many linux servers with my own script. I often have new samples that are not in my existing rules, I've wanted a way to be able to ingest my rules into TheHive, I was using the yara analyzer but it has had some hiccups with v2 of Cortex. This led me to build the following using the base code from other scanners.

walk through provided here:
https://laskowski-tech.com/2018/07/24/clamav-analyzer-for-thehive-and-cortex/

@3c7 3c7 added category:enhancement Issue is related to an existing feature to improve scope:analyzer Issue is analyzer related status:pr-submitted status:needs-review labels Jul 25, 2018
@jeromeleonard jeromeleonard added this to the 2.5.0 milestone Jan 20, 2020
@dadokkio dadokkio changed the base branch from master to develop February 18, 2020 09:25
dadokkio pushed a commit that referenced this pull request Feb 18, 2020
Extend pull request #312
Fixes code issues and long report template
Improve naming for folder and files
nadouani pushed a commit that referenced this pull request Feb 18, 2020
Extend pull request #312
Fixes code issues and long report template
Improve naming for folder and files
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:enhancement Issue is related to an existing feature to improve scope:analyzer Issue is analyzer related status:needs-review status:pr-submitted
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants