TheHive-Project / TheHive-Project/Cortex-Analyzers

[Bug] PassiveTotal analyzers : Unexpected Error

Open
#1,044 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
490
Forks
405
Avg merge
2d 43m
Merged PRs (30d)
8

Description

Describe the bug
PassiveTotal analyzers are not working. It doesn't matter which analyzer or type of data to analyze.

To Reproduce
Steps to reproduce the behavior:

  1. Adding one of the PassiveTotal analyzer by entering username and key
  2. Start a new analysis with this analyzer

Expected behavior
Correct operation or at least a more detailed description of the errors so that it could be solved somehow.

Complementary information
The error that appears:
"Unexpected Error: <Response [429]>"

I checked by running locally and also using cortexneurons.
Same error.

By logging into the RiskIQ account of the analyzer, I can see that there are many possible number of queries.

Work environment

  • Server OS: Ubuntu 20.04
  • Cortex version: 3.1.1-1
  • Cortex Analyzer/Responder name: PassiveTotal_Components_2_0 and others from this group
  • Cortex Analyzer/Responder version: 2.0

Possible solutions
Maybe the analyzer is executing too many queries at once? Maybe it can be somehow limited or delayed.

Additional context
Add any other context about the problem here.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the failure with PassiveTotal_Components_2_0 or another PassiveTotal analyzer using the supplied Cortex and analyzer versions. Investigate the reported HTTP 429 response and determine whether the analyzer behavior needs rate limiting or clearer error reporting; done means the analyzer operates correctly or exposes an actionable error.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.