TheHive-Project / TheHive-Project/Cortex
Issues with cortex Analyzers
Nobody has claimed this yet.
- Dominant language
- Scala
- Stars
- 1.6k
- Forks
- 264
- PR merge metrics
- No merged PRs in 30d
Description
Request Type
Issue
Work Environment
| Question | Answer |
|---|---|
| OS version (server) | CentOS |
| Cortex version | 3.1.1-1 |
| Package Type | Docker |
Problem Description
I have installed cortex analyzers using this link combined with , but some analyzers doesn't work.
I have pyhon 2.7 and 3.7 installed.
Steps to Reproduce
- Open Cortex Web
- launch Abuse_Finder_3_0
- Run analyzers
- Go to Job report
Traceback (most recent call last): File "/usr/lib/python3.7/sre_parse.py", line 1021, in parse_template this = chr(ESCAPES[this][1])KeyError: '\s'During handling of the above exception, another exception occurred:Traceback (most recent call last): File "/opt/Cortex-Analyzers/analyzers/Abuse_Finder/abusefinder.py", line 9, in from abuse_finder import domain_abuse, ip_abuse, \ File "/usr/local/lib/python3.7/dist-packages/abuse_finder/init.py", line 2, in from .domain import domain_abuse File "/usr/local/lib/python3.7/dist-packages/abuse_finder/domain.py", line 3, in from pythonwhois.net import get_whois_raw File "/usr/local/lib/python3.7/dist-packages/pythonwhois/init.py", line 1, in from . import net, parse File "/usr/local/lib/python3.7/dist-packages/pythonwhois/parse.py", line 363, in registrant_regexes = [preprocess_regex(regex) for regex in registrant_regexes] File "/usr/local/lib/python3.7/dist-packages/pythonwhois/parse.py", line 363, in registrant_regexes = [preprocess_regex(regex) for regex in registrant_regexes] File "/usr/local/lib/python3.7/dist-packages/pythonwhois/parse.py", line 205, in preprocess_regex regex = re.sub(r"\s*(?P<([^>]+)>.+)", r"\s*(?P<\1>\S.*)", regex) File "/usr/lib/python3.7/re.py", line 192, in sub return _compile(pattern, flags).sub(repl, string, count) File "/usr/lib/python3.7/re.py", line 309, in _subx template = _compile_repl(template, pattern) File "/usr/lib/python3.7/re.py", line 300, in _compile_repl return sre_parse.parse_template(repl, pattern) File "/usr/lib/python3.7/sre_parse.py", line 1024, in parse_template raise s.error('bad escape %s' % this, len(this))re.error: bad escape \s at position 0
Possible Solutions
I'm not sure if it's related to python environment because i tried to change from 2 to python3.
Complementary information

Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Reproduce the failure by launching Abuse_Finder_3_0 in Cortex 3.1.1-1 and review the traceback beginning in analyzers/Abuse_Finder/abusefinder.py and continuing through pythonwhois/parse.py. Compare the Python 2.7 and 3.7 environments and the installed dependencies. Done means the analyzer completes without the reported regular-expression error and produces a job report.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, python
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100