TheHive-Project / TheHive-Project/Cortex
Analyzer Grouping
@To-om is already working on this.
Since May 23, 2018.
- Dominant language
- Scala
- Stars
- 1.6k
- Forks
- 264
- PR merge metrics
- No merged PRs in 30d
Description
Request Type
Feature Request
Work Environment
| Question | Answer |
|---|---|
| Cortex version / git hash | 2.x |
Problem Description
As suggested by @garanews, in some situations, it would be nice to group analyzers so that analysts can, for example, know which analyzers they should run first, second and so on.
Possible Solutions
Analyzer descriptions should contain an additional field to 'clusterize' analyzers and group them to the administrator likings/requirements. This grouping should be exposed through the API, allowing tools such as TheHive to display the grouping and allow analysts to execute 'clusters' of analyzers over specific observables at once.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.