Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

codecov

Join us on Slack!

Click here and fill out the form to receive an invite to the Open Cybersecurity Alliance slack instance, then join the #stix-shifter channel, to meet and discuss usage with the team.

Introduction Webinar!

Click here to view an introduction webinar on STIX Shifter and the use cases it solves for.

Introduction

STIX-shifter is an open source python library allowing software to connect to products that house data repositories by using STIX Patterning, and return results as STIX Observations.

For more information about this project, see the STIX-shifter Overview

Dependencies

This stix-shifter has the following dependencies:

Your development environment must use Python version: 3.6, 3.7, 3.8 or 3.9

Installation

The recommended method for installing the STIX-shifter is via pip. Two prerequisite packages needs to be installed inlcuding the package of stix-shifter connector module to complete a stix-shifter connector installation. Run below commands to install all the packages-

  1. Main stix-shifter package: pip install stix-shifter

  2. Stix-shifter Utility package: pip install stix-shifter-utils

  3. Desired stix-shifter connector module package: pip install stix-shifter-modules-<module name> Example: pip install stix-shifter-modules-qradar

Usage

As A Command Line Utility

The STIX-Shifter comes with a bundled script which you can use to translate STIX Pattern to a native datasource query. It can also be used to translate a JSON data source query result to a STIX bundle of observable objects. You can also send query to a datasource by using a transmission option.

More details of the command line option can be found here

$ stix-shifter translate <MODULE NAME> query "<STIX IDENTITY OBJECT>" "<STIX PATTERN>" "<OPTIONS>"

Example:

$ stix-shifter translate qradar query {} "[ipv4-addr:value = '127.0.0.1']" {}

In order to build stix-shifter packages from source follow the below prerequisite steps:

  1. Go to the stix-shifter parent directory
  2. Optionally, you can create a Python 3 virtual environemnt: virtualenv -p python3 virtualenv && source virtualenv/bin/activate
  3. Run setup: python3 setup.py install

Running From the Source

You may also use python3 main.py script. All the options are the same as "As a command line utility" usage above.

Example:

python3 main.py translate qradar query {} "[ipv4-addr:value = '127.0.0.1']" {}

In order to run python3 main.py from the source follow the below prerequisite steps:

  1. Go to the stix-shifter parent directory
  2. Optionally, you can create a Python 3 virtual environemnt: virtualenv -p python3 virtualenv && source virtualenv/bin/activate
  3. Run setup to install dependancies: INSTALL_REQUIREMENTS_ONLY=1 python3 setup.py install.

Note: setup.py only installs dependencies when INSTALL_REQUIREMENTS_ONLY=1 directive is used. This option is similar to python3 generate_requirements.py && pip install -r requirements.txt

As A Library

You can also use this library to integrate STIX Shifter into your own tools. You can translate a STIX Pattern:

from stix_shifter.stix_translation import stix_translation

translation = stix_translation.StixTranslation()
response = translation.translate('<MODULE NAME>', 'query', '{}', '<STIX PATTERN>', '<OPTIONS>')

print(response)

Contributing

We are thrilled you are considering contributing! We welcome all contributors.

Please read our guidelines for contributing.

Guide for creating new connectors

If you want to create a new connector for STIX-shifter, see the developer guide

Licensing

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

More Resources

Release files for stix-shifter-modules-proofpoint 4.0.1.dev654

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distribution (wheel)

Table of built distributions (wheels) for stix-shifter-modules-proofpoint 4.0.1.dev654
File Interpreter ABI Platform
stix_shifter_modules_proofpoint-4.0.1.dev654-py2.py3-none-any.whl Python 2, Python 3 none any Details

Release files / stix_shifter_modules_proofpoint-4.0.1.dev654-py2.py3-none-any.whl

Download URL stix_shifter_modules_proofpoint-4.0.1.dev654-py2.py3-none-any.whl
Size 37.0 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
615fa3a300c058fdb16bbdf48c0acb2dcc13ee069608ed14f7428ac29eff51cf
BLAKE2b-256 checksum
How to use checksums
333ca3074a6c632781e4872164afaa4ba3c1f4ed88767aa86ed8035aa3c10931
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.8.0 pkginfo/1.8.2 readme-renderer/34.0 requests/2.27.1 requests-toolbelt/0.9.1 urllib3/1.26.9 tqdm/4.63.1 importlib-metadata/4.11.3 keyring/23.5.0 rfc3986/2.0.0 colorama/0.4.4 CPython/3.9.5

Release history Release notifications | RSS feed

8.1.2

1 release file

8.1.1

1 release file

8.1.0

1 release file

8.0.4

1 release file

8.0.3

1 release file

8.0.2

1 release file

8.0.1

1 release file

8.0.0

1 release file

7.1.6

1 release file

7.1.5

1 release file

7.1.4

1 release file

7.1.3

1 release file

7.1.2

1 release file

7.1.1

1 release file

7.1.0

1 release file

7.0.12

1 release file

7.0.11

1 release file

7.0.10

1 release file

7.0.9

1 release file

7.0.7

1 release file

7.0.6

1 release file

7.0.4

1 release file

7.0.2

1 release file

7.0.1

1 release file

7.0.0

1 release file

6.3.0

1 release file

6.2.2

1 release file

6.2.1

1 release file

6.2.0

1 release file

6.1.1

1 release file

6.1.0

1 release file

6.0.4

1 release file

6.0.3

1 release file

6.0.2

1 release file

6.0.1

1 release file

6.0.0

1 release file

5.3.2

1 release file

5.3.1

1 release file

5.3.0

1 release file

5.2.1

1 release file

5.1.1

1 release file

5.1.0

1 release file

5.0.2

1 release file

5.0.1

1 release file

5.0.0

1 release file

4.6.10

1 release file

4.6.8

1 release file

4.6.7

1 release file

4.6.6

1 release file

4.6.5

1 release file

4.6.4

1 release file

4.6.3

1 release file

4.6.2

1 release file

4.6.1

1 release file

4.6.0

1 release file

4.5.2

1 release file

4.5.1

1 release file

4.4.0

1 release file

4.3.1

1 release file

4.3.0

1 release file

4.2.6

1 release file

4.2.5

1 release file

4.2.4

1 release file

4.2.3

1 release file

4.2.2

1 release file

4.2.1

1 release file

4.2.0

1 release file

4.1.1

1 release file

4.1.0

1 release file

4.0.17

1 release file

4.0.16

1 release file

4.0.15

1 release file

4.0.14

1 release file

4.0.13

1 release file

4.0.12

1 release file

4.0.11

1 release file

4.0.10

1 release file

4.0.9

1 release file

4.0.8

1 release file

4.0.7

1 release file

4.0.6

1 release file

4.0.5

1 release file

4.0.4

1 release file

4.0.3

1 release file

4.0.2

1 release file

4.0.1

1 release file

This release

4.0.1.dev654 This release

1 release file

4.0.0

1 release file

3.6.11

1 release file

3.6.10

1 release file

3.6.9

1 release file

3.6.8

1 release file

3.6.6

1 release file

3.6.5

1 release file

3.6.4

1 release file

3.6.3

1 release file

3.6.2

1 release file

3.6.1

1 release file

3.6.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page