Comments (3)
Should be part of the 4.5 release of Assemblyline:
https://github.com/CybercentreCanada/assemblyline/releases/tag/v4.5.0.stable1
from assemblyline.
Perhaps the attribution field can be used for this?
I didn't see that before making this issue.
from assemblyline.
We may not be able to show all the metadata associated to a badlist match in the way you described (in a single section) as the reasons can vary and can be classified at different levels, in which case we'd have to split up the reasoning as a subsection of the IOC hit (something we currently do now but the presentation can be improved).
In regards to metadata such as "Added On" (added
) and "Last Updated" (updated
), we can add that metadata for context since it's behind the classification of the badlist item itself but we aren't able to distinguish between when one source "added" the item vs another: we just know when it was added/updated to the system in general but not by whom:
https://github.com/CybercentreCanada/assemblyline-service-badlist/blob/0d1d22668d4a5e5fd609a68069a0c7263c09c80e/badlist/badlist.py#L118-L129
from assemblyline.
Related Issues (20)
- Cannot submit archived expired file
- Wrong file type identification - Python as INI HOT 4
- Missed .online static domain HOT 1
- UI: Badlisted tags are not colored in file details view HOT 2
- Scaler to recognize service in failed state HOT 2
- Suricata service can be stuck for hours if suricata didn't start HOT 5
- Health checks for services are broken in Docker Compose HOT 1
- Update service stays in a loop trying to install obsoletes or non accessible docker images. HOT 1
- Intezer-Analyze short-circuit download
- Feature Request: tolerations and nodeAffinity HOT 12
- Identity: Python obfuscated code identified as text/plain HOT 4
- Suricata 4.5.0.7 seems to be broken HOT 1
- Expose `delete_file_from_filestore` API to Python Client HOT 1
- Allow "private" submissions
- FrankenStrings URL extraction seems to trim URLs on char 0, even when it's not a binary file HOT 2
- AL 4.5.0.27: updater cannot upgrade any service HOT 15
- YARA service cannot parse rules with negative integers in metadata HOT 4
- Signature update services may not expose new signatures for workers immediately
- Unable to setup - Kibana keeps failing HOT 8
- Error: 504 Gateway-Timeout when all containers are up and healthy. HOT 5
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from assemblyline.