forked from csirtgadgets/csirtg-smrt-v1
-
Notifications
You must be signed in to change notification settings - Fork 0
the SMRT Book
Scott Finlon edited this page May 31, 2019
·
12 revisions
- Fetch
- Listening
- Parse
- Map
- Output
- Cacheing data feeds - is the data feed new
- State - remembers intelligence seem previously
$ [sudo] pip install csirtg-smrt
https://github.com/csirtgadgets/csirtg-smrt-py/tree/master/csirtg_smrt/parser
- delimited (csv, tsv, pipe, etc)
- json
- xml
- stix
- cef
- cifv2
- cifv3
- json
- bind
- bro
- snort
- csv
- table
https://github.com/csirtgadgets/csirtg-indicator-py/tree/master/csirtg_indicator/format
- stdin
- stdout
- http
- syslog
- zmq
https://github.com/csirtgadgets/csirtg-smrt-py/tree/master/csirtg_smrt/client
- cif
- splunk
- elasticsearch
- zyre
- bro
- sie
- Spamhaus
- Dataplane
- ...
Describe the rules configuration
- https://github.com/csirtgadgets/csirtg-indicator-py/blob/master/csirtg_indicator/constants.py#L31
- Changes:
- otype -> itype
- observable -> indicator
- confidence -> 1-10
- Previous: https://github.com/csirtgadgets/massive-octo-spice/blob/develop/src/rules/example/csv_example.yml