TheHive-Project / TheHive-Project/Cortex

Issues with cortex Analyzers

Open
#352 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Scala
Stars
1.6k
Forks
264
PR merge metrics
No merged PRs in 30d

Description

Request Type
Issue

Work Environment
Question Answer
OS version (server) CentOS
Cortex version 3.1.1-1
Package Type Docker
Problem Description

I have installed cortex analyzers using this link combined with , but some analyzers doesn't work.

I have pyhon 2.7 and 3.7 installed.

Steps to Reproduce
  1. Open Cortex Web
  2. launch Abuse_Finder_3_0
  3. Run analyzers
  4. Go to Job report

Traceback (most recent call last): File "/usr/lib/python3.7/sre_parse.py", line 1021, in parse_template this = chr(ESCAPES[this][1])KeyError: '\s'During handling of the above exception, another exception occurred:Traceback (most recent call last): File "/opt/Cortex-Analyzers/analyzers/Abuse_Finder/abusefinder.py", line 9, in from abuse_finder import domain_abuse, ip_abuse, \ File "/usr/local/lib/python3.7/dist-packages/abuse_finder/init.py", line 2, in from .domain import domain_abuse File "/usr/local/lib/python3.7/dist-packages/abuse_finder/domain.py", line 3, in from pythonwhois.net import get_whois_raw File "/usr/local/lib/python3.7/dist-packages/pythonwhois/init.py", line 1, in from . import net, parse File "/usr/local/lib/python3.7/dist-packages/pythonwhois/parse.py", line 363, in registrant_regexes = [preprocess_regex(regex) for regex in registrant_regexes] File "/usr/local/lib/python3.7/dist-packages/pythonwhois/parse.py", line 363, in registrant_regexes = [preprocess_regex(regex) for regex in registrant_regexes] File "/usr/local/lib/python3.7/dist-packages/pythonwhois/parse.py", line 205, in preprocess_regex regex = re.sub(r"\s*(?P<([^>]+)>.+)", r"\s*(?P<\1>\S.*)", regex) File "/usr/lib/python3.7/re.py", line 192, in sub return _compile(pattern, flags).sub(repl, string, count) File "/usr/lib/python3.7/re.py", line 309, in _subx template = _compile_repl(template, pattern) File "/usr/lib/python3.7/re.py", line 300, in _compile_repl return sre_parse.parse_template(repl, pattern) File "/usr/lib/python3.7/sre_parse.py", line 1024, in parse_template raise s.error('bad escape %s' % this, len(this))re.error: bad escape \s at position 0

Possible Solutions

I'm not sure if it's related to python environment because i tried to change from 2 to python3.

Complementary information

image

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the failure by launching Abuse_Finder_3_0 in Cortex 3.1.1-1 and review the traceback beginning in analyzers/Abuse_Finder/abusefinder.py and continuing through pythonwhois/parse.py. Compare the Python 2.7 and 3.7 environments and the installed dependencies. Done means the analyzer completes without the reported regular-expression error and produces a job report.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, python
Domain
backend, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.