MISP / MISP/misp-modules

Extremely new to this - Trying to get Crowdstrike module to work

Open
#408 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
377
Forks
280
Avg merge
2d 2h
Merged PRs (30d)
10

Description

Hi everyone, as the title shows I'm very new. I am trying to integrate MISP with our Crowdstrike instance. Here are the steps I took so far, but I cannot determine if this is working.
-Created an event with google.com and a known SHA256 file hash as attributes
-Published the event to my organization only
-Input QUERYAPIUSER and QUERYAPIKEY into the module
-Turned module on for my ORG only

I am seeing no feedback/sightings for the events, even though I know they should be getting hit on. Am I missing any steps or is there a way for me to verify if the API is correctly running? Thank you.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The report concerns a MISP event, the CrowdStrike integration, and the QUERYAPIUSER and QUERYAPIKEY module settings, but names no file, test, or reproducible error. Start by reproducing the reported lack of feedback or sightings and verify whether the module is receiving the published event. Done should include a confirmed cause and a documented verification path or a focused bug report with reproduction steps.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
api, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.