Skip to main content

iocingestor

PyPI version Python CI Coverage Status CodeFactor

An extendable tool to extract and aggregate IoCs from threat feeds.

This tool is a forked version of InQuest's ThreatIngestor focuses on MISP integration.

Key differences

  • Better MISP integration.
    • Working with the latest version of MISP.
    • Smart event management based on reference_link.
  • MISP warninglist compatible whitelisting.
  • Using ioc-finder instead of iocextract for IoC extraction.
    • YARA rule extraction is dropped.

Installation

iocingestor requires Python 3.6+.

Install iocingestor from PyPI:

pip install iocingestor

Usage

Create a new config.yml file, and configure each source and operator module you want to use. (See config.example.yml as a reference.)

iocingestor config.yml

By default, it will run forever, polling each configured source every 15 minutes.

Plugins

iocingestor uses a plugin architecture with "source" (input) and "operator" (output) plugins. The currently supported integrations are:

Sources

  • GitHub repository search
  • RSS feeds
  • Twitter
  • Generic web pages

Operators

  • CSV files
  • MISP
  • SQLite database

Metadata

Release files for iocingestor 0.3.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for iocingestor 0.3.3
File Size Uploaded
iocingestor-0.3.3.tar.gz 31.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for iocingestor 0.3.3
File Interpreter ABI Platform
iocingestor-0.3.3-py3-none-any.whl Python 3 none any Details

Total release size: 71.9 kB

Release files / iocingestor-0.3.3.tar.gz

Download URL iocingestor-0.3.3.tar.gz
Size 31.7 kB
Tags Source
SHA-256 checksum
How to use checksums
7239316ce214662b2dae196d2b63f5e187d202652923e494fe818b6d524b2d30
BLAKE2b-256 checksum
How to use checksums
2708fe9ecd01997061fddb968bd5ac53528261171692fcc5a06fca2747cf20a5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.1.8 CPython/3.8.2 Darwin/20.6.0

Release files / iocingestor-0.3.3-py3-none-any.whl

Download URL iocingestor-0.3.3-py3-none-any.whl
Size 40.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
967740b6122aaab905c6c42ad574165947d9ada0e27adcc2e74fcc467c9f5d20
BLAKE2b-256 checksum
How to use checksums
35a7d494294385ee282bc3b712f72d23168548e6846fca14925b1eede67d8ccf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.1.8 CPython/3.8.2 Darwin/20.6.0

Release history Release notifications | RSS feed

This release

0.3.3 This release

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page