TheHive-Project / TheHive-Project/Cortex-Analyzers

[FR] Migrate analyzer jsons to new documentation

Open
#873 2 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

category:feature-request help wanted
Dominant language
Python
Stars
490
Forks
405
Avg merge
2d 43m
Merged PRs (30d)
8

Description

Following instruction https://thehive-project.github.io/Cortex-Analyzers/analyzers_definition/ could be useful to update old analyzers json with subscribtion informations, README and logo.
Analyzers and responders with missing info are:

Dead services?

  • BackscatterIO
  • C1fApp
  • Hippocampe

OLD API

  • HybridAnalysis

Analyzers not docker-able

  • CERTatPassiveDNS
  • ClamAV
  • FireHOLBlocklists
  • Malpedia

Analyzers

  • Abuse_Finder
  • AbuseIPDB
  • AnyRun
  • Autofocus
  • Censys
  • CIRCLPassiveDNS
  • CIRCLPassiveSSL
  • Crtsh
  • CuckooSandbox
  • CyberChef
  • CyberCrime
  • Cyberprotect
  • DNSLookingglass
  • DNSDB
  • DNSSinkhole
  • DomainMailSPFDMARC
  • DomainTools
  • DomainTools Iris
  • DShield
  • Elasticsearch
  • EmailRep
  • EmergingThreats
  • EmlParser
  • FileInfo
  • FireEyeiSight
  • ForcePoint Websense
  • Fortiguard
  • GoogleDNS
  • GoogleSafebrowsing
  • GoogleVisionAPI
  • GreyNoise
  • Hashdd
  • HIBP
  • Hunterio
  • IBMXForce
  • Inoitsu
  • IntezerCommunity
  • Investigate
  • IPinfo
  • IPVoid
  • JoeSandbox
  • LastInfoSec
  • Ldap
  • Maltiverse
  • MalwareBazaar
  • MalwareClustering
  • Malwares
  • MaxMind
  • MetaDefender
  • MISP
  • MISPWarningLists
  • MnemonicPDNS
  • MsgParser
  • Nerd
  • Nessus
  • NSRL
  • Onyphe [missing readme]
  • OpenCTI [missing readme and long template]
  • OTXQuery
  • PassiveTotal
  • Patrowl
  • PayloadSecurity
  • PhishingInitiative
  • PhishTank
  • ProofPoint
  • Pulsedive
  • RecordedFuture
  • Robtex
  • Sekoia
  • SecurityTrails
  • Shodan
  • SinkDB
  • SoltraEdge
  • SophosIntelix
  • Spamassassin
  • SpamhausDBL
  • Splunk
  • StaxxSearch
  • StopForumSpam
  • TalosReputation
  • TeamCymruMHR
  • ThorThunderstorm
  • Threatcrowd
  • ThreatGrid
  • ThreatResponse
  • TorBlutmagie
  • TorProject
  • Umbrella
  • UnshortenLink
  • URLhaus
  • Urlscan
  • Valhalla
  • Virusshare
  • VirusTotal
  • VMRay
  • Vulnerns
  • WOT
  • Yara
  • Yeti

Responders

  • AMPforEndpoints
  • CheckPoint
  • DNS-RPZ
  • DomainTools Iris
  • FalconCustomIOC
  • KnowBe4
  • Mailer
  • MailIncidentStatus
  • Minemeld *
  • QRadar
  • Redmine
  • RT4
  • SendGrid
  • Shuffle
  • UmbrellaBlacklister
  • Velociraptor
  • VirustotalDownloader *
  • Wazuh
  • ZEROFOX

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the linked analyzer-definition documentation and inspect the old analyzer JSON files, README files, and logos for the unchecked analyzers and responders. Confirm which services are still available and which entries need subscription information or updated metadata. Done means the applicable checklist entries have current JSON metadata, README content, and logos, with unavailable services identified.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.