-
Notifications
You must be signed in to change notification settings - Fork 382
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
McAfee ATD Analyzer #25
Comments
Hi @bullerdude. As for FireEye AX, we do not have access to an instance hence if you or someone would be willing to create an analyzer for it or give us access to one... you may contact us on our support email address if you'd like to discuss this. Thanks. |
Hi @saadkadhi, we are keen to develop this analyser. We will develop the code using a forked repository - https://github.com/UNIT777/Cortex-Analyzers. |
Thanks @bullerdude. Once your analyzer is ready, please submit a pull request so we integrate it to the analyzer list. Also, let us know if we can be of any help for coding the analyzer. Once it is dubbed ready for production, we will work on TheHive's short and long report templates. For that, we will need some sample outputs from the analyzer. Otherwise, if you feel confortable with AngularJS, please go ahead and provide short and long report templates so we can package them and share them with the community. Thanks a heap for your help. |
Hi @bullerdude. Any update on this front? Thanks a lot. |
Hey @saadkadhi, i will check up on this. I was looking to build a tool to poke ATD and I discovered Cortex, which is what i wanted. I plan to do this this during this month. By that time, if @bullerduke have something, let us know. |
Yes we have the integration working; it required a custom piece of middleware to work around session management issues in the ATD API.
Will try to get it uploaded during the week.
…________________________________
From: nacc3ss <notifications@github.com>
Sent: Saturday, November 4, 2017 3:10:18 PM
To: CERT-BDF/Cortex-Analyzers
Cc: Matthew Rankin; Mention
Subject: Re: [CERT-BDF/Cortex-Analyzers] McAfee ATD Analyzer (#25)
Hey @saadkadhi<https://github.com/saadkadhi>, i will check up on this. I was looking to build a tool to poke ATD and I discovered Cortex, which is what i wanted. I plan to do this this during this month. By that time, if @bullerduke have something, let us know.
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub<#25 (comment)>, or mute the thread<https://github.com/notifications/unsubscribe-auth/AFKrD5H-HRNa5ncGKO0qIJCq1KPhExIpks5sy-OqgaJpZM4MfY5Q>.
|
Hey, Is there an update on this? Would really love to integrate with ATD. Ed |
Request Type
Analyzer Request
Work Environment
N/A
Problem Description
Create an analyzer that will submit files to a local McAfee ATD sandbox instance and retrieve the report and indicators that are generated
The text was updated successfully, but these errors were encountered: