Coder Social home page Coder Social logo

stephen-oleary / cortex-analyzers Goto Github PK

View Code? Open in Web Editor NEW

This project forked from thehive-project/cortex-analyzers

0.0 0.0 0.0 18.94 MB

Cortex Analyzers Repository

Home Page: https://thehive-project.org

License: GNU Affero General Public License v3.0

Python 52.38% C 1.73% HTML 45.34% Shell 0.48% Dockerfile 0.07%

cortex-analyzers's People

Contributors

3c7 avatar ag-michael avatar amr-cossi avatar ant1 avatar colinsheppard10 avatar crackytsi avatar dadokkio avatar garanews avatar ilyaglow avatar iosonogio avatar jeromeleonard avatar jonashergenhahn avatar ktneely avatar kx499 avatar makyotox avatar megan201296 avatar mlodic avatar nadouani avatar ndejong avatar ninoseki avatar ninsmith avatar saadkadhi avatar sigalpes avatar siisar avatar srilumpa avatar stephen-oleary avatar syloktools avatar to-om avatar xme avatar yugoslavskiy avatar

cortex-analyzers's Issues

Enable extraction of observables from static/dynamic analysis reports[FR]

Feature description
Automatically extract observables such as file hashes, URLs, domains, IPs etc from the contents of the reports and add them to the case

Describe the solution you'd like
Dynamic analysis shows network traffic, DNS requests, HTTP flow and various other data that may be useful to track, static analysis shows nearest neighbor files, which could potentially be useful, but probably less so. Would be good to extract all this data and add to the case.

Dynamic Analysis Screenshots Section should only show if there are screenshots available[Bug]

Describe the bug
If there are no screenshots available in a dynamic analysis report, the section heading still displays in the report

To Reproduce
Run dynamic analysis that does not generate screenshots

Expected behavior
If there are no screenshots the heading should not appear

Possible solutions
Probably need to add/amend the ng-if statement on the div containing the screenshots

Enable Retrieving Static/Dynamic Analysis Reports via File Hash[FR]

Feature description
For the static/dynamic analysis reports, the API allows you to retrieve the report by using the SHA256 file hash so even if you didn't have the file, you could get the report if it had been submitted previously

Describe the solution you'd like
Allow the analyzer to work on hash datatype
For hash datatype attempt to retrieve the report via the SHA256 hash and display it if it exists, otherwise return the message that no report is available until the file is submitted

File hash lookup should return more data[FR]

Feature description
Currently the file hash lookup only returns the classification of the file, there is more data that could be exposed such as the reputation score and the detection signature

Describe the solution you'd like
Return the more detailed information and update the long template to display it correctly

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.