iocingestor
An extendable tool to extract and aggregate IoCs from threat feeds.
This tool is a forked version of InQuest's ThreatIngestor focuses on MISP integration.
Key differences
- Better MISP integration.
- Working with the latest version of MISP.
- Smart event management based on
reference_link.
- MISP warninglist compatible whitelisting.
- Using ioc-finder instead of iocextract for IoC extraction.
- YARA rule extraction is dropped.
Installation
iocingestor requires Python 3.6+.
Install iocingestor from PyPI:
pip install iocingestor
Usage
Create a new config.yml file, and configure each source and operator module you want to use. (See config.example.yml as a reference.)
iocingestor config.yml
By default, it will run forever, polling each configured source every 15 minutes.
Plugins
iocingestor uses a plugin architecture with "source" (input) and "operator" (output) plugins. The currently supported integrations are:
Sources
- GitHub repository search
- RSS feeds
- Generic web pages
Operators
- CSV files
- MISP
- SQLite database
Metadata
Release files for iocingestor 0.3.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| iocingestor-0.3.3.tar.gz | 31.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| iocingestor-0.3.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 71.9 kB
Release files / iocingestor-0.3.3.tar.gz
| Download URL | iocingestor-0.3.3.tar.gz |
|---|---|
| Size | 31.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7239316ce214662b2dae196d2b63f5e187d202652923e494fe818b6d524b2d30
|
|
BLAKE2b-256 checksum How to use checksums |
2708fe9ecd01997061fddb968bd5ac53528261171692fcc5a06fca2747cf20a5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
poetry/1.1.8 CPython/3.8.2 Darwin/20.6.0
|
Release files / iocingestor-0.3.3-py3-none-any.whl
| Download URL | iocingestor-0.3.3-py3-none-any.whl |
|---|---|
| Size | 40.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
967740b6122aaab905c6c42ad574165947d9ada0e27adcc2e74fcc467c9f5d20
|
|
BLAKE2b-256 checksum How to use checksums |
35a7d494294385ee282bc3b712f72d23168548e6846fca14925b1eede67d8ccf
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
poetry/1.1.8 CPython/3.8.2 Darwin/20.6.0
|