TheHive-Project / TheHive-Project/Cortex

Analyzer Grouping

Open
#66 1 comment 0 reactions 2 assignees View on GitHub

@To-om is already working on this.

Since May 23, 2018.

feature request
Dominant language
Scala
Stars
1.6k
Forks
264
PR merge metrics
No merged PRs in 30d

Description

Request Type

Feature Request

Work Environment
Question Answer
Cortex version / git hash 2.x
Problem Description

As suggested by @garanews, in some situations, it would be nice to group analyzers so that analysts can, for example, know which analyzers they should run first, second and so on.

Possible Solutions

Analyzer descriptions should contain an additional field to 'clusterize' analyzers and group them to the administrator likings/requirements. This grouping should be exposed through the API, allowing tools such as TheHive to display the grouping and allow analysts to execute 'clusters' of analyzers over specific observables at once.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.