[whoisfreaks] Fix WHOIS/DNS mapping, migrate DNS to v2.0, add IP and domain-reputation enrichment - #805
Open
Usama015 wants to merge 2 commits into
Open
[whoisfreaks] Fix WHOIS/DNS mapping, migrate DNS to v2.0, add IP and domain-reputation enrichment#805Usama015 wants to merge 2 commits into
Usama015 wants to merge 2 commits into
Conversation
… and domain-reputation enrichment Reworks the WhoisFreaks expansion/hover module (bumped to version 3) to fix incorrect attribute mapping, migrate to the current API endpoints, and support IP and domain-reputation enrichment. The module now uses the misp_standard format and runs every API call for a given attribute in parallel. Docs updated accordingly.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Reworks the WhoisFreaks expansion/hover module (now version 3):
mapping (verified against the WhoisFreaks API response schema).
v1.0/dns/liveendpoint tothe current
v2.0/dns/live.misp_standardformat and running all API calls for an attribute in parallel.
New functionality
domainstix2-pattern,whoisfreaks-domain-reputationobject, verdict/severity/action tagsip-src/ip-dst/ipgeolocation+asnobjects,whoisfreaks-ip-securityobject, abuse-contact/netblock attributes, security-flag tags"format": "misp_standard"; the module now returns MISPattributes, objects and tags.
(
ThreadPoolExecutor), so response time tracks the slowest single callrather than the sum.