MISP / MISP/PyMISP

Creating a MISPGalaxyCluster

Open
#730 14 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

T: support
Dominant language
Python
Stars
491
Forks
290
Avg merge
2d 8h
Merged PRs (30d)
3

Description

@tomking2 would you happen to have an example on how to create and add a galaxy cluster?

I started out with something like this.. but it didn't turn out right. Tag contained the uuid and such:

cluster = MISPGalaxyCluster()
cluster["description"] = "UNK:ursu"
cluster["value"] = "ursu"
cluster["tag_name"] = 'misp-galaxy:avclass="ursu"'
cluster["distribution"] = 3
cluster["type"] = "avclass"
cluster["source"] = "AvClass"
pymisp.add_galaxy_cluster(galaxy, cluster)

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the reported MISPGalaxyCluster and pymisp.add_galaxy_cluster example in the issue, then inspect the corresponding PyMISP galaxy-cluster API entry points. Done means providing a documented, working creation example that clarifies the required fields and how the cluster is added.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
api
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.