Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New analyzer: NERD #816

Merged
merged 3 commits into from
Aug 10, 2020
Merged

New analyzer: NERD #816

merged 3 commits into from
Aug 10, 2020

Conversation

vaclavbartos
Copy link
Contributor

Added a new analyzer to get data from CESNET's Network Entity Reputation Database (NERD) (see https://nerd.cesnet.cz/).

Templates for The Hive are included.

If you want to test it, you'll need an API key - write me to bartos@cesnet.cz and I'll create you an account (unfortunatelly a feature to create account in NERD by yourself is not finished yet).

Note: I'm one of the authors and maintainer of NERD.

Added a new analyzer to get data from CESNET's Network Entity Reputation Database (NERD). Templates for The Hive are included.
@dadokkio
Copy link
Contributor

dadokkio commented Jul 14, 2020

Just tested, nice templates 😃

image

image

There is just a missing quote in the url field in nerd.json file that need to be fixed and imho for no-data is better to keep the results as info and not as safe, what do you think?

Since you are going to update that file if you want you can add new analyzer information, your logo and screenshots that will be shown in the new documentation.
You can read more about this here: https://thehive-project.github.io/Cortex-Analyzers/analyzers_definition/

@dadokkio dadokkio added this to the 2.9.0 milestone Jul 14, 2020
@vaclavbartos
Copy link
Contributor Author

Thanks for the feedback and suggestions. I added some more information. I would add the logo and screenshots, too, but I don't know where to put the files to. The example shows the assets directory, but I can't find it anywhere.

@dadokkio
Copy link
Contributor

You can add an assets folder in your code at the same level of the nerd.json.. the idea is that each analyzer will have an assets folder. you can see this approach already used in iris or spamassassin pulls

@vaclavbartos
Copy link
Contributor Author

Thanks, I added the images.

@To-om To-om force-pushed the develop branch 3 times, most recently from fb8f5aa to 23be632 Compare July 29, 2020 15:56
@dadokkio dadokkio merged commit 4450424 into TheHive-Project:develop Aug 10, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants