InQuest / InQuest/ThreatKB

Add option in mass import to mass retire IOCs

Open
#460 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement threat-intel
Dominant language
JavaScript
Stars
104
Forks
17
PR merge metrics
No merged PRs in 30d

Description

We can currently resurrect existing retired IOCs imported via https://threatkb.inquest.net/#!/import. This is a feature request to add an option to retire imported IOCs if they exist in ThreatKB and are in "Released" state.

  • Ability to quick filter for key timestamp fields on indicators (evaluate as "if (date_now) > the timestamp field"):
    • Expiration timestamps
    • Next review on timestamp

This applies to indicators (C2 IP, C2 domains).

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the mass-import page at https://threatkb.inquest.net/#!/import and trace how imported indicators are matched to existing ThreatKB records and their "Released" state. Review how C2 IP and C2 domain timestamp fields are handled; done means imports can optionally retire matching released indicators and can filter by expiration or next-review timestamps.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
web-dev
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.